PT-2025-35494 · Knowage · Knowage

Dedalus95

·

Published

2025-09-01

·

Updated

2025-09-01

·

CVE-2025-55007

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Knowage versions prior to 8.1.37
Description Knowage is vulnerable to server-side request forgery. The vulnerability allows attackers to send requests to arbitrary hosts/paths. The impact of this vulnerability is limited as attackers cannot read the response, but it could be leveraged to scan the internal network.
Recommendations Update to version 8.1.37 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55007
GHSA-7F6M-PH57-52W6

Affected Products

Knowage