Tophat versions prior to 2.5.1, a mobile applications testing harness, are vulnerable to remote code execution through unsanitized URL parameter handling in tophat:// or http://localhost:29070 URLs. The arguments query parameter flows directly to /bin/bash -c execution without sanitization, enabling attackers to run arbitrary commands on affected developer macOS workstations with user-level permissions. The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and user authentication. Notably, previously trusted build hosts bypass confirmation dialogs, and command execution occurs with full user privileges, resulting in high impact across confidentiality, integrity, and availability. The FAUCET Risk Score of 53.0/100 indicates elevated risk warranting immediate remediation. While the vulnerability is listed as actively monitored on the Hot List, it is not currently tracked in the Known Exploited Vulnerabilities catalog and remains relatively uncommon compared to other CVEs based on EPSS scoring. However, the presence on the Hot List and the straightforward exploitation mechanism suggest heightened community attention and moderate risk of practical exploitation. Organizations should prioritize upgrading Tophat to version 2.5.1 or later across all developer workstations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.1CPE matchmatch criteria | cpe:2.3:a:shopify:tophat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.