Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dyad
Dyad dyad |
|
Vendors & Products |
Dyad
Dyad dyad |
Wed, 17 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 17 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later. | |
Title | Dyad Vulnerable to Remote Code Execution via Top-level Navigation in Preview Window | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-17T17:51:53.392Z
Reserved: 2025-09-04T19:18:09.500Z
Link: CVE-2025-58766

Updated: 2025-09-17T17:50:41.458Z

Status : Awaiting Analysis
Published: 2025-09-17T18:15:52.687
Modified: 2025-09-18T13:43:34.310
Link: CVE-2025-58766

No data.