GNU Bash OS Command Injection Vulnerability
GNU · GNU Bash
CVSS 8.8
EPSS 100%
5 public exploits
Fix deadline passed 23 October 2025
What it is
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
Why we say that
- EPSS puts exploitation in the next 30 days at 100%
- 5 public exploits published
- CISA's federal remediation deadline (2025-10-23) has passed
- Listed in the CISA Known Exploited Vulnerabilities catalogue
Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.
What to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Public exploit code
Indexed from Exploit-DB. Presence of code raises urgency; absence does not mean safety.
- Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
- Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)
- Apache mod_cgi - 'Shellshock' Remote Command Injection
- GNU bash 4.3.11 - Environment Variable dhclient
- dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
What it costs when this goes wrong
This is where UK enforcement meets the vulnerability record. Where an unfixed vulnerability leads to a breach, the ICO treats it as a security failure under UK GDPR. Recent cases:
- The Electoral Commission Reprimand issued to the Electoral Commission in respect of Articles 5(1)(f) and 32(1)(b). Between 24 August 2021 and 27 October 20…
- Gain Capital UK Limited Gain Capital UK have been issued a Reprimand in respect of Articles 32 (2) and 32 (1) (b). An unauthorised third party leveraged a…
- Chartered Institute for Securities & Investment An unauthorised third party exploited a known vulnerability in the Sitefinity software to leverage a bruteforce attack to upload a…