CVE Explorer
CVE-2026-33147
GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue occurs when a specially crafted long string is passed as a dataset identifier (e.g., via the which module), leading to a crash or potential arbitrary code execution. This issue has been patched via commit 0ad2b49.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"gmt","vendor":"GenericMappingTools","versions":[{"status":"affected","version":"<= 6.6.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121: Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/GenericMappingTools/gmt/commit/0ad2b491470df82c9ec1139dcbd70502fa28a082","tags":["x_refsource_MISC"],"url":"https://github.com/GenericMappingTools/gmt/commit/0ad2b491470df82c9ec1139dcbd70502fa28a082"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/adp/0/references/0
{"name":"https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/GenericMappingTools/gmt/security/advisories/GHSA-fqxx-62x7-9gwg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ffd8bd7cdbe252b144c33b863a3f03fe893d0b1bcab5f608169b288807b0d69a · sha256:f5f7477882ae9a42… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.