Cockpit Hq · Cockpit · CVE-2025-1025
**Name of the Vulnerable Software and Affected Versions**
cockpit-hq/cockpit versions prior to 2.4.1
**Description**
The issue allows for Arbitrary File Upload, where an attacker can bypass the upload filter by using different extensions.
**Recommendations**
For cockpit-hq/cockpit versions prior to 2.4.1, consider restricting file uploads or implementing additional validation to prevent bypassing the upload filter until a patch is available.