CVE-2024-48990
HIGH 7.8EPSS 20.5%
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 20.45% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2024-11-19
- Updated
- 2025-11-03
Proof-of-concept exploits (21)
- Cyb3rFr0g/CVE-2024-48990-PoC2★ · 2024-11-24
- CyberCrowCC/CVE-2024-489900★ · 2024-12-09
- NullByte-7w7/CVE-2024-489901★ · 2024-12-19
- ally-petitt/CVE-2024-48990-Exploit5★ · 2024-11-25
- felmoltor/CVE-2024-489900★ · 2024-11-22
- makuga01/CVE-2024-48990-PoC105★ · 2024-11-20
- ns989/CVE-2024-489905★ · 2024-11-22
- pentestfunctions/CVE-2024-48990-PoC-Testing26★ · 2024-11-24
- ten-ops/CVE-2024-48990_needrestart5★ · 2025-02-16
- ProsteKubo/npm_poisoning_poc0★ · 2026-08-26
- BLUEBERRYP1LL/CVE-2024-48990
- Loaxert/CVE-2024-48990-PoC
- Mr-DJ/CVE-2024-48990
- Serner77/CVE-2024-48990-Automatic-Exploit
- czeti/CVE-2024-48990_needrestart
- grecosamuel/CVE-2024-48990
- kikechans/-Linux-PrivEsc-CVE-2024-48990
- mladicstefan/CVE-2024-48990
- o-sec/CVE-2024-48990
- sobbing333/CVE-2024-48990-POC
- tahsinunluturk/needrestart-privesc-cve-2024-48990