Skip to main content

CVE-2025-58766: CWE-94: Improper Control of Generation of Code ('Code Injection') in dyad-sh dyad

Critical
VulnerabilityCVE-2025-58766cvecve-2025-58766cwe-94
Published: Wed Sep 17 2025 (09/17/2025, 17:36:22 UTC)
Source: CVE Database V5
Vendor/Project: dyad-sh
Product: dyad

Description

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-09-04T19:18:09.500Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68caf2f2822eeeec0bbb2583

Added to database: 9/17/2025, 5:42:10 PM

Last updated: 9/17/2025, 5:42:10 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats