CVE-2025-27616
Last modified
CVE-2025-27616 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a specific set of headers and body data, an attacker could transfer ownership of a repository and its repo level secrets to a separate repository. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Prior to versions 0.25.3 and 0.26.3, by spoofing a webhook payload with a specific set of headers and body data, an attacker could transfer ownership of a repository and its repo level secrets to a separate repository. These secrets could be exfiltrated by follow up builds to the repository. Users with an enabled repository with access to repo level CI secrets in Vela are vulnerable to the exploit, and any user with access to the CI instance and the linked source control manager can perform the exploit. Versions 0.25.3 and 0.26.3 fix the issue. No known workarounds are available.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27616?
How severe is CVE-2025-27616?
How do I fix CVE-2025-27616?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27610Rack provides an interface for developing web applications i…7.5
- CVE-2025-27611base-x is a base encoder and decoder of any given alphabet u…8.7
- CVE-2025-27612libcontainer is a library for container control. Prior to li…5.9
- CVE-2025-27613Gitk is a Tcl/Tk based Git history browser. Starting with 1.…3.6
- CVE-2025-27614Gitk is a Tcl/Tk based Git history browser. Starting with 2.…8.6
- CVE-2025-27615umatiGateway is software for connecting OPC Unified Architec…8.2
- CVE-2025-27617Pimcore is an open source data and experience management pla…8.8
- CVE-2025-2762CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege …7.8
- CVE-2025-27622Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not …4.3
- CVE-2025-27623Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not …4.3
- CVE-2025-27624A cross-site request forgery (CSRF) vulnerability in Jenkins…5.4
- CVE-2025-27625In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redir…4.3
Are you affected by CVE-2025-27616?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
