Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-41717

Опубликовано: 13 янв. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

EPSS

Процентиль: 29%
0.00105
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
22 дня назад

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

EPSS

Процентиль: 29%
0.00105
Низкий

8.8 High

CVSS3

Дефекты

CWE-94