CVE-2025-53813

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
26/08/2025
Last modified:
26/08/2025

Description

The configuration of Nozbe on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Nozbe TCC (Transparency, Consent, and Control) permissions. <br /> Acquired resource access is limited to previously granted permissions by the user. Access to other resources beyond granted-permissions requires user interaction with a system prompt asking for permission.<br /> <br /> This issue was fixed in version 2025.11 of Nozbe.

References to Advisories, Solutions, and Tools