PT-2025-26595 · Brain2 · Brain2

Published

2025-06-23

·

Updated

2025-06-28

·

CVE-2025-6512

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: BRAIN2 versions 0.0 through 3.05
Description: A script can be integrated into a report on a client with a non-admin user. The reports could later be executed on the BRAIN2 server with administrator rights, potentially allowing for code injection. This issue is related to improper control of generation of code.
Recommendations: For BRAIN2 versions 0.0 through 3.05, update to a version later than 3.05 to resolve the issue. As a temporary workaround, consider restricting the execution of reports on the BRAIN2 server to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14623
CVE-2025-6512

Affected Products

Brain2