vulns.comcp

← CVE intelligence

CVE-2014-6278 - GNU Bash OS Command Injection Vulnerability

GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.

Severity
critical
Product
GNU GNU Bash
Published
2025-10-02
EPSS
0.996
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.