Nask · Pib Botsense · CVE-2025-1774
**Name of the Vulnerable Software and Affected Versions**
NASK - PIB BotSense versions prior to 2.8.0
**Description**
The issue is related to incorrect string encoding, allowing the injection of an additional field separator character or value in certain fields of generated events. This can include adding a field with extra separator characters or values to the `extraData` field.
**Recommendations**
For versions prior to 2.8.0, update to version 2.8.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `extraData` field until a patch is available. Avoid using the `extraData` field in a way that could allow injection of additional field separator characters or values.