PT-2025-37088 · Hoverfly · Hoverfly

·

CVE-2025-54123

·

Published

2025-09-10

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hoverfly versions prior to 1.12.0
Description Insufficient validation and sanitization of user input in the middleware functionality allows for command injection. The issue resides in the middleware management API endpoint /api/v2/hoverfly/middleware and results from a combination of three flaws: insufficient input validation in middleware.go, unsafe command execution in local middleware.go, and immediate execution during testing in hoverfly service.go. An attacker can exploit this to achieve remote code execution (RCE) on the host server with the privileges of the Hoverfly process by passing malicious payloads or arbitrary commands, such as reverse shells, through the binary and script variables.
Recommendations Update to version 1.12.0. As a temporary workaround, restrict access to the /api/v2/hoverfly/middleware API endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54123
GHSA-R4H8-HFP2-GGMF
GO-2025-3944
OPENSUSE-SU-2025:15564-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2025:03289-1

Affected Products

Hoverfly