V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-65741
DEB
CriticalConfirmedExploit available

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execut…

CVSS
9.8
Critical
EPSS
0.00
p35
Published
2025-01-01
Updated
2025-01-01
Description

Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the Sublime Text application.

Tags · CWE
Pre-auth
CWE-427
CAPEC-38
CAPEC-471
Affected products
Sublime_text_3 < 3.2.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.004 · p35
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-471 · CWE-427
└ via CAPEC-471 · CWE-427
Known exploits — Сканер-ВС
CVE-2025-65741
github-poc · https://github.com/vinicius-batistella/CVE-2025-65741
Enterprise
Affected products
ProductVendorStatus
sublime-textTracked
sublime_text_3*Tracked