Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

rootio-python3.11: Unauthenticated Remote Code Execution

ROOT-OS-DEBIAN-12-CVE-2025-15366
Summary

An attacker can execute arbitrary code on a system using rootio-python3.11 without needing a password. This affects Root users who have installed the rootio-python3.11 package on Debian 12. To protect your system, update to the latest version of rootio-python3.11.

What to do
  • Update rootio-python3.11 to version 3.11.2-6+deb12u6.root.io.25.
Affected software
VendorProductAffected versionsFix available
– rootio-python3.11 <= 3.11.2-6+deb12u6.root.io.25 3.11.2-6+deb12u6.root.io.25
Original title
CVE-2025-15366 in rootio-python3.11 - Patched by Root
Original description
Root has patched CVE-2025-15366 in the rootio-python3.11 package for Root:Debian:12. Multiple fixed versions available.
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026