Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
CVE ID: CVE-2024-48990
CVSS Base Severity: HIGH
CVSS Base Score: 7.8
Vendor: needrestart
Product: needrestart
EPSS Score: 0.25% (probability of being exploited)
EPSS Percentile: 64.67% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)