Impact
A command injection flaw in eObčanka‑Identifikace’s AppleScript wrapper allows an attacker to supply arbitrary command line input through a custom URL scheme, resulting in arbitrary code execution on a MacOS system. The vulnerability stems from unsanitized concatenation of URL parameters into an OS command, which can be exploited to run any command with the privileges of the application.
Affected Systems
Digitální a informační agentura (DIA) vulnerable versions include all releases before v3.6.0. The 3.6.0 update (released 2026‑05‑13) added AppleScript sanitization, and v3.7.0 (released 2026‑07‑17) eliminated AppleScript from the bundle entirely, removing the attack surface.
Risk and Exploitability
With a CVSS score of 9.3 this flaw represents a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker who can trigger the custom URL scheme (czeeopauth://) by sending a crafted link or executing a command locally can inject OS commands that run with the application’s permissions. Successful exploitation requires that the application be installed on a MacOS machine; once triggered, the attacker can gain full control over the system, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment