CVE-2025-39664

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Oct 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-09 15:16

Updated : 2025-10-13 15:16


NVD link : CVE-2025-39664

Mitre link : CVE-2025-39664

CVE.ORG link : CVE-2025-39664


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')