CVE-2025-2733
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 352
Summary
CVE-2025-2733 is a critical vulnerability affecting mannaandpoem OpenManus versions up to 2025.3.13. The issue lies in the Prompt Handler component's app/tool/python_execute.py file, which contains an unknown part susceptible to os command injection. An attacker can exploit this remotely, leading to significant security risks. The vulnerability has been disclosed to the public, and there is evidence that it is being actively exploited. Despite early notification, the vendor has not responded to address the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress