CVE-2025-66223
Last modified
CVE-2025-66223 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. This results in broken access control where a removed or demoted user can regain access or escalate privileges. This issue has been patched in version 0.16.0.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-66223?
How severe is CVE-2025-66223?
How do I fix CVE-2025-66223?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-66216AIS-catcher is a multi-platform AIS receiver. Prior to versi…9.8
- CVE-2025-66217AIS-catcher is a multi-platform AIS receiver. Prior to versi…7.5
- CVE-2025-66219willitmerge is a command line tool to check if pull requests…9.8
- CVE-2025-66220Envoy is a high-performance edge/middle/service proxy. In 1.…7.1
- CVE-2025-66221Werkzeug is a comprehensive WSGI web application library. Pr…5.3
- CVE-2025-66222DeepChat is a smart assistant uses artificial intelligence. …9.6
- CVE-2025-66224OrangeHRM is a comprehensive human resource management (HRM)…8.8
- CVE-2025-66225OrangeHRM is a comprehensive human resource management (HRM)…8.8
- CVE-2025-66228Rejected reason: Not used
- CVE-2025-66229Rejected reason: Not used
- CVE-2025-66230Rejected reason: Not used
- CVE-2025-66231Rejected reason: Not used
Are you affected by CVE-2025-66223?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
