CVE-2025-32918: Livestatus injection in autocomplete endpoint
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32918?
CVE-2025-32918 has been assessed as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2025-32918?
To fix CVE-2025-32918, upgrade Checkmk to version 2.4.0p6 or later, or patch the affected versions as advised by the vendor.
Who is affected by CVE-2025-32918?
CVE-2025-32918 affects users of Checkmk versions prior to 2.4.0p6, 2.3.0p35, and 2.2.0p44.
What type of vulnerability is CVE-2025-32918?
CVE-2025-32918 is classified as an improper neutralization of Livestatus command delimiters, allowing for command injection.
Can CVE-2025-32918 be exploited remotely?
CVE-2025-32918 requires authentication, so it cannot be exploited remotely without valid credentials.