PT-2025-44396 · Checkmk · Checkmk

Lisa Gnedt

·

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2025-39663

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.4.0p14 Checkmk versions prior to 2.3.0p39 Checkmk versions 2.2.0 Checkmk version 2.1.0
Description A Cross-Site Scripting (XSS) issue exists in Checkmk's distributed monitoring functionality. A compromised remote site can inject malicious HTML code into service outputs on the central site. This allows for potential JavaScript injection and Remote Code Execution (RCE) in distributed setups.
Recommendations Versions prior to 2.4.0p14 should be updated. Versions prior to 2.3.0p39 should be updated. For version 2.2.0, consider disabling “Trust this site completely”. For version 2.1.0, consider disabling “Trust this site completely”.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-39663

Affected Products

Checkmk