PT-2025-43531 · Kottster · Kottster

Published

2025-10-23

·

Updated

2025-10-28

·

CVE-2025-62713

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Kottster versions 3.2.0 through 3.3.1
Description Kottster is a self-hosted Node.js admin panel. Versions 3.2.0 through 3.3.1 contain a pre-authentication remote code execution (RCE) vulnerability when running in development mode. Production deployments are not affected.
Recommendations Update to version 3.3.2 or later.

Exploit

Fix

RCE

Improper Access Control

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-62713
GHSA-J3W7-9QC3-G96P

Affected Products

Kottster