Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in version 8.1.27.
References
Link | Resource |
---|---|
https://github.com/KnowageLabs/Knowage-Server/commit/1bb60d42557724f7ed24c19df6c5017e169527ca | Patch |
https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-96cv-75hg-xrgq | Exploit Vendor Advisory |
https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-96cv-75hg-xrgq | Exploit Vendor Advisory |
Configurations
History
08 Oct 2025, 15:08
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://github.com/KnowageLabs/Knowage-Server/commit/1bb60d42557724f7ed24c19df6c5017e169527ca - Patch | |
References | () https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-96cv-75hg-xrgq - Exploit, Vendor Advisory | |
First Time |
Eng knowage
Eng |
|
CPE | cpe:2.3:a:eng:knowage:*:*:*:*:*:*:*:* |
30 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-96cv-75hg-xrgq - |
30 Sep 2025, 11:37
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-30 11:37
Updated : 2025-10-08 15:08
NVD link : CVE-2025-59954
Mitre link : CVE-2025-59954
CVE.ORG link : CVE-2025-59954
JSON object : View
Products Affected
eng
- knowage
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')