CVE-2025-30289: ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability of CVE-2025-30289?
CVE-2025-30289 is an OS Command Injection vulnerability in ColdFusion that can lead to arbitrary code execution.
What versions of ColdFusion are affected by CVE-2025-30289?
CVE-2025-30289 affects ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier.
What are the potential risks of exploiting CVE-2025-30289?
Exploitation of CVE-2025-30289 can result in arbitrary code execution, allowing attackers to execute harmful commands on the server.
How can I mitigate the risk of CVE-2025-30289?
To mitigate CVE-2025-30289, upgrade to a patched version of ColdFusion that addresses this vulnerability.
Is authentication required to exploit CVE-2025-30289?
Exploiting CVE-2025-30289 does not require authentication, making it a critical security concern.