← Back to browse · API

CVE-2025-34300

Severity
CRITICAL
CVSS
10.0
EPSS
0.5108
Risk score
57.88
CISA KEV
No
PoC
No
Published
2025-07-16
Modified
2026-05-26
First seen
2026-08-07
Aliases
EUVD-2025-21694, GHSA-M8MC-QPG2-G56X
Products
Sawtooth Software:Lighthouse Studio 0 <9.16.14
Sources
euvd EUVD-2025-21694

Description

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.

References