CNNVD-202506-2647 Information
Jun 20, 2025
cve
CNNVD ID
CNNVD-202506-2647
Related CVE
- CNNVD Published: 2025-06-20
Description (Chinese)
Core.ai Phoenix Code是印度Core.ai公司的一个轻量级的文本编辑器。 Core.ai Phoenix Code存在安全漏洞,该漏洞源于允许动态库注入,可能导致本地攻击者绕过TCC。
Description (English)
Core.ai Phoenix Code is a lightweight text editor for Core.ai, India. Core.ai Phoenix Code has a security loophole, which stems from allowing a dynamic bank to be injected and could lead local attackers to bypass TCC.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Core.ai
Published
2025-06-20
Last Modified
2026-02-24
References
https://cert.pl/en/posts/2025/06/tcc-bypass/ https://github.com/phcode-dev/phoenix-desktop/pull/623/commits/0c75fb57f89d0b7d9b180026bc2624b7dcf807da https://phcode.dev/
Patch
https://github.com/phcode-dev/phoenix-desktop/releases
Share on: