This page aggregates publicly disclosed CVE and security risk information related to shirt-pocket, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-69604 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | [email protected] | 7.8 | 0.10% | 2026-01-29 | 2026-07-04 |
| CVE-2025-61229 | An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | [email protected] | 7.8 | 0.12% | 2025-12-01 | 2026-07-04 |
| CVE-2025-61228 | An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism | [email protected] | 7.8 | 0.09% | 2025-12-01 | 2026-07-04 |
| CVE-2025-57489 | Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary. | [email protected] | 8.1 | 0.30% | 2025-12-01 | 2026-07-04 |