← Back to browse · API

CVE-2025-32463

Severity
CRITICAL
CVSS
9.3
EPSS
0.54935
Risk score
81.43
CISA KEV
Yes
PoC
Yes
Published
2025-09-29
Modified
2025-09-29
First seen
2026-08-07
Aliases
EUVD-2025-19673, GHSA-695J-C63M-MVXC
Products
Sudo project:sudo 1.9.14 <1.9.17p1, Sudo:Sudo
Sources
github 8574c26434c27a8157e761b8|CVE-2025-32463
euvd EUVD-2025-19673
cisa.gov CVE-2025-32463
github b00b0653530992ccb21492e8|CVE-2025-32463

Description

Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.

References