Vulnerability Description
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/CHOOCS/fe1227443544d5d74c33982814f290af
- https://github.com/Cockpit-HQ/Cockpit/commit/984ef9ad270357b843af63c81db95178eae
- https://github.com/Cockpit-HQ/Cockpit/commit/becca806c7071ecc732521bb5ad0bb9c642
- https://security.snyk.io/vuln/SNYK-PHP-COCKPITHQCOCKPIT-8516320
- https://gist.github.com/CHOOCS/fe1227443544d5d74c33982814f290af
FAQ
What is CVE-2025-1025?
CVE-2025-1025 is a vulnerability with a CVSS score of 7.5 (HIGH). Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
How severe is CVE-2025-1025?
CVE-2025-1025 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1025?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.