CVE-2025-50125
Last modified
CVE-2025-50125 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-50125?
How severe is CVE-2025-50125?
How do I fix CVE-2025-50125?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-50110An issue was discovered in the method push.lite.avtech.com.A…8.8
- CVE-2025-5012The Workreap plugin for WordPress, used by the Workreap - Fr…8.8
- CVE-2025-50121A CWE-78: Improper Neutralization of Special Elements used i…9.5
- CVE-2025-50122A CWE-331: Insufficient Entropy vulnerability exists that co…8.9
- CVE-2025-50123A CWE-94: Improper Control of Generation of Code ('Code Inj…7.2
- CVE-2025-50124A CWE-269: Improper Privilege Management vulnerability …7.2
- CVE-2025-50126A stored XSS vulnerability in the RSBlog! component 1.11.6-1…5.3
- CVE-2025-50127A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Jooml…8.5
- CVE-2025-50128A cross-site scripting (xss) vulnerability exists in the vid…6.1
- CVE-2025-50129A memory corruption vulnerability exists in the PCX Image De…8.8
- CVE-2025-5013A vulnerability, which was classified as problematic, was fo…4.7
- CVE-2025-50130A heap-based buffer overflow vulnerability exists in VS6Sim.…8.4
Are you affected by CVE-2025-50125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
