PatchSiren debrief for CVE-2026-48098 based on the supplied source corpus. NexTor IP Changer, a command-line tool leveraging the Tor network for IP address rotation, had a vulnerability in versions prior to 2.0.0. The tool executed privileged system commands using `sudo` and `shell=True` directly in application logic. This could allow for silent execution of privileged commands in environments with passwo [truncated]
PatchSiren debrief for CVE-2026-48097: A command execution vulnerability exists in NexTor IP Changer versions prior to 2.0.0 due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables earlier in the `PATH`, resulting in execution of attacker-controlled code. Ve [truncated]