CVE-2025-54374
Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted eidos: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (eidos:), causing the Eidos application to launch and process the URL, leading to remote code execution on the victim’s machine. This issue does not have a fix as of October 3, 2025
Published:Oct 3, 2025
Last Modified:Oct 24, 2025
EPS:Oct 3, 2025
EPSS Score:0.00139
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Eidos
Product
Eidos
Eidos
Eidos
Vendor
Mayneyao
Product
Eidos
Mayneyao
Eidos
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
