
Two NSIS CVEs in play: CVE-2023-37378 - weak ACLs on the uninstaller temp directory, exploitable via DotLocal redirection or NTFS junction swaps CVE-2025-43715 - race condition in plugin directory creation, letting an attacker hijack $PLUGINSDIR before it's locked down
Post summary
The text provides technical details about two NSIS vulnerabilities but lacks evidence of active exploitation, PoC, patch, or deprecation.
