CVE-2025-62376
Last modified
CVE-2025-62376 is a critical-severity vulnerability rated 9.5/10 on the CVSS scale. pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker to access any active Windows VM without proper authorization. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker to access any active Windows VM without proper authorization. The vulnerability occurs in the view_desktop function where the user is retrieved via a URL parameter without verifying that the requester has administrative privileges. An attacker can supply any user ID and arbitrary password in the request parameters to impersonate another user. When requesting a Windows desktop service, the function does not validate the supplied password before generating access credentials, allowing the attacker to obtain an iframe source URL that grants full access to the target user's Windows VM. This impacts all users with active Windows VMs, as an attacker can access and modify data on the Windows machine and in the home directory of the associated Linux machine via the Z: drive. This issue has been patched in commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef. No known workarounds exist.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-62376?
How severe is CVE-2025-62376?
How do I fix CVE-2025-62376?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62370Alloy Core libraries at the root of the Rust Ethereum ecosys…7.5
- CVE-2025-62371OpenSearch Data Prepper as an open source data collector for…7.4
- CVE-2025-62372vLLM is an inference and serving engine for large language m…6.5
- CVE-2025-62373Pipecat is an open-source Python framework for building real…9.8
- CVE-2025-62374Parse Javascript SDK provides access to the powerful Parse S…6.4
- CVE-2025-62375go-witness and witness are Go modules for generating attesta…6.9
- CVE-2025-62378CommandKit is the discord.js meta-framework for building Dis…6.1
- CVE-2025-62379Reflex is a library to build full-stack web apps in pure Pyt…3.1
- CVE-2025-6238The AI Engine plugin for WordPress is vulnerable to open red…8
- CVE-2025-62380mailgen is a Node.js package that generates responsive HTML …2.9
- CVE-2025-62381sveltekit-superforms makes SvelteKit forms a pleasure to use…8.3
- CVE-2025-62382Frigate is a network video recorder (NVR) with realtime loca…7.7
Are you affected by CVE-2025-62376?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
