Vulnerability Description
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Homebrew/homebrew-core/issues/35085
- https://github.com/traviscross/mtr/blob/master/SECURITY
- https://github.com/traviscross/mtr/commit/5226f105f087c29d3cfad9f28000e7536af91a
- https://github.com/traviscross/mtr/blob/master/SECURITY
FAQ
What is CVE-2025-49809?
CVE-2025-49809 is a vulnerability with a CVSS score of 7.8 (HIGH). mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect conse...
How severe is CVE-2025-49809?
CVE-2025-49809 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-49809?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.