CVE-2025-54389
Last modified
CVE-2025-54389 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tamper with the log output. A local user might exploit this to bypass the AIDE detection of malicious files. Additionally the output of extended attribute key names and symbolic links targets are also not properly neutralized. This issue has been patched in version 0.19.2. A workaround involves configuring AIDE to write the report output to a regular file, redirecting stdout to a regular file, or redirecting the log output written to stderr to a regular file.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Advanced Intrusion Detection Environment Project | Advanced Intrusion Detection Environment | < 0.19.2 |
References
- https://github.com/aide/aide/releases/tag/v0.19.2Release Notes
- https://github.com/aide/aide/security/advisories/GHSA-522j-vvx9-gg28Exploit, Mitigation, Vendor Advisory
- https://github.com/aide/aide/security/advisories/GHSA-522j-vvx9-gg28Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-54389?
How severe is CVE-2025-54389?
How do I fix CVE-2025-54389?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-54382Cherry Studio is a desktop client that supports for multiple…8.8
- CVE-2025-54384CKAN is an open-source DMS (data management system) for powe…6.3
- CVE-2025-54385XWiki Platform is a generic wiki platform offering runtime s…9.8
- CVE-2025-54386Traefik is an HTTP reverse proxy and load balancer. In versi…9.8
- CVE-2025-54387IPX is an image optimizer powered by sharp and svgo. In vers…9.8
- CVE-2025-54388Moby is an open source container framework developed by Dock…4.6
- CVE-2025-5439A vulnerability was found in Linksys RE6500, RE6250, RE6300,…8.8
- CVE-2025-54390A Cross-Site Request Forgery (CSRF) vulnerability exists in …6.3
- CVE-2025-54391A vulnerability in the EnableTwoFactorAuthRequest SOAP endpo…9.1
- CVE-2025-54392Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.…6.1
- CVE-2025-54393Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.…5.4
- CVE-2025-54394Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.…5.3
Are you affected by CVE-2025-54389?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
