Vulnerability Description
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Lymphatus/caesium-image-compressor
- https://github.com/Lymphatus/caesium-image-compressor/blob/main/src/utils/PostCo
- https://github.com/Lymphatus/caesium-image-compressor/pull/376
- https://github.com/mertsatilmaz/vulnerability-research/blob/main/advisories/CVE-
FAQ
What is CVE-2026-36365?
CVE-2026-36365 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions...
How severe is CVE-2026-36365?
CVE-2026-36365 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-36365?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.