CVE-2025-8700 describes a vulnerability in Invoice Ninja on macOS, where the "com.apple.security.get-task-allow" entitlement permits local unprivileged attackers to attach a debugger, modify process memory, and inject code, bypassing Hardened Runtime and TCC. This medium-severity flaw (CVSS 4.8) allows access to resources previously granted by the user, without requiring administrator credentials for debugger attachment. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability, which was fixed in Invoice Ninja version 5.0.175.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 5.0.175CPE match | cpe:2.3:a:invoiceninja:invoice_ninja:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.