PT-2025-38699 · Unknown+1 · Lightspeed+1

Published

2025-06-10

·

Updated

2025-09-27

·

CVE-2025-5962

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lightspeed (affected versions not specified)
Description A flaw exists in the Lightspeed history service due to insufficient access controls. A local, unprivileged user can access and manipulate the chat history of another user on the same system. An attacker can view, delete, or inject arbitrary history entries, potentially deceiving another user into executing harmful actions through social engineering, leading to privilege misuse or unauthorized command execution. The issue involves abusing inter-process communication calls to the history service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-5962
INFSA-2025_16346
RHSA-2025:16345
RHSA-2025:16346
RHSA-2025_16346

Affected Products

Lightspeed
Red Hat