PT-2025-5346 · Unknown+1 · Vaultwarden+1

Elizarbatin

·

Published

2024-06-25

·

Updated

2025-08-20

·

CVE-2025-24364

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vaultwarden version 1.33.0 and earlier
Description The issue allows an attacker with authenticated access to the vaultwarden admin panel to execute arbitrary code in the system. This can be achieved by changing settings to use sendmail as a mail agent, adjusting the settings to use a shell command, and crafting a special favicon image with embedded commands to run during certain actions, such as sending a test email. The vulnerability is reported to affect a significant number of devices, given vaultwarden's popularity, with estimates suggesting it is used in 10% of all companies in some countries.
Recommendations For versions prior to 1.33.0, update to version 1.33.0 to fix the vulnerability. As a temporary workaround, consider disabling the sendmail functionality and restricting access to the admin panel until the update can be applied. Additionally, restrict access to the favicon image upload feature to minimize the risk of exploitation.

Exploit

Fix

LPE

Special Elements Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5575
BDU:2025-05022
CVE-2025-24364
GHSA-H6CC-RC6Q-23J4

Affected Products

Alt Linux
Vaultwarden