Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This behavior bypasses standard security restrictions that normally prevent code execution in regular Maple worksheets. The vulnerability enables attackers to craft malicious .maplet files that execute arbitrary code without user interaction.
Metrics
Affected Vendors & Products
References
History
Sat, 23 Aug 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Maplesoft
Maplesoft maple |
|
Vendors & Products |
Maplesoft
Maplesoft maple |
Fri, 22 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 21 Aug 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This behavior bypasses standard security restrictions that normally prevent code execution in regular Maple worksheets. The vulnerability enables attackers to craft malicious .maplet files that execute arbitrary code without user interaction. | |
Title | Maple <= v13 Maplet File Creation and Command Execution | |
Weaknesses | CWE-94 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-21T20:12:54.367Z
Updated: 2025-08-22T15:25:43.410Z
Reserved: 2025-08-20T20:33:55.844Z
Link: CVE-2010-20120

Updated: 2025-08-22T15:25:33.065Z

Status : Awaiting Analysis
Published: 2025-08-21T21:15:34.507
Modified: 2025-08-22T18:08:51.663
Link: CVE-2010-20120

No data.