CVE-2025-13428: RCE in SecOps SOAR server via user-provided Python packages
A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validation of uploaded Python package code. An attacker could upload a package containing a malicious setup.py file, which would execute on the server during the installation process, leading to potential server compromise.
No customer action is required.
All customers have been automatically upgraded to the fixed version: 6.3.64 or higher.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13428?
CVE-2025-13428 is classified as a critical vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-13428?
To fix CVE-2025-13428, update the SecOps SOAR server to the latest version beyond 6.3.64.
Who is impacted by CVE-2025-13428?
CVE-2025-13428 affects all users of the SecOps SOAR server versions prior to 6.3.64.
What are the attack vectors for CVE-2025-13428?
CVE-2025-13428 can be exploited by authenticated users with an IDE role through weak validation of uploaded Python packages.
What are the consequences of exploiting CVE-2025-13428?
Exploitation of CVE-2025-13428 can lead to Remote Code Execution on the vulnerable SecOps SOAR server.