← Back to browse · API

CVE-2025-1025

Severity
HIGH
CVSS
8.7
EPSS
0.19493
Risk score
41.62
CISA KEV
No
PoC
No
Published
2025-02-05
Modified
2026-08-03
First seen
2026-08-07
Aliases
EUVD-2025-0244, GHSA-WP68-XRFG-XVQ4
Products
cockpit-hq:cockpit-hq/cockpit 0 <2.4.1
Sources
euvd EUVD-2025-0244

Description

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

References