PT-2025-33680 · Komari · Komari

Imlonghao

·

Published

2025-08-12

·

Updated

2025-08-21

·

CVE-2025-55300

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Komari versions prior to 1.0.4-fix1
Description: Komari is a server monitoring tool. A Cross-Site WebSocket Hijacking (CSWSH) issue exists in the WebSocket upgrader due to disabled origin checking, potentially allowing remote code execution against authenticated users. An attacker can send requests to the terminal websocket endpoint with the victim's browser cookies.
Recommendations: Update to version 1.0.4-fix1 or later.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55300
GHSA-Q355-H244-969H
GO-2025-3874

Affected Products

Komari