PT-2025-5346 · Unknown+1 · Vaultwarden+1

Elizarbatin

·

Publicado

2024-06-25

·

Atualizado

2025-08-20

·

CVE-2025-24364

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vaultwarden version 1.33.0 and earlier
Description The issue allows an attacker with authenticated access to the vaultwarden admin panel to execute arbitrary code in the system. This can be achieved by changing settings to use sendmail as a mail agent, adjusting the settings to use a shell command, and crafting a special favicon image with embedded commands to run during certain actions, such as sending a test email. The vulnerability is reported to affect a significant number of devices, given vaultwarden's popularity, with estimates suggesting it is used in 10% of all companies in some countries.
Recommendations For versions prior to 1.33.0, update to version 1.33.0 to fix the vulnerability. As a temporary workaround, consider disabling the sendmail functionality and restricting access to the admin panel until the update can be applied. Additionally, restrict access to the favicon image upload feature to minimize the risk of exploitation.

Exploit

Correção

LPE

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-5575
BDU:2025-05022
CVE-2025-24364
GHSA-H6CC-RC6Q-23J4

Produtos afetados

Alt Linux
Vaultwarden