CVE-2025-39664: Path-Traversal in report scheduler
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39664?
CVE-2025-39664 is considered a medium severity vulnerability due to insufficient escaping in the report scheduler.
How does CVE-2025-39664 affect Checkmk users?
CVE-2025-39664 allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
Which versions of Checkmk are affected by CVE-2025-39664?
CVE-2025-39664 affects Checkmk versions earlier than 2.4.0p13, 2.3.0p38, and 2.2.0p46.
How do I fix CVE-2025-39664?
To fix CVE-2025-39664, upgrade your Checkmk installation to a version that is not vulnerable, specifically 2.4.0p13 or later.
Can CVE-2025-39664 be exploited by unauthenticated users?
No, CVE-2025-39664 requires authentication to exploit, limiting the attacker to authenticated users.