CVE-2025-48868: Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE) vulnerability exists in Horilla 1.3.0 due to the unsafe use of Python’s eval() function on a user-controlled query parameter in the projectbulkarchive view. This allows privileged users (e.g., administrators) to execute arbitrary system commands on the server. While having Django’s DEBUG=True makes exploitation visibly easier by returning command output in the HTTP response, this is not required. The vulnerability can still be exploited in DEBUG=False mode by using blind payloads such as a reverse shell, leading to full remote code execution. This issue has been patched in version 1.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Horillato a version that resolves this vulnerability.Fixed in 1.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48868?
The severity of CVE-2025-48868 is critical due to the potential for Remote Code Execution.
How do I fix CVE-2025-48868?
To fix CVE-2025-48868, update Horilla to the latest version that addresses the vulnerability.
What versions of Horilla are affected by CVE-2025-48868?
CVE-2025-48868 affects Horilla version 1.3.0.
Can CVE-2025-48868 be exploited without authentication?
No, CVE-2025-48868 requires an authenticated user to exploit the vulnerability.
What is the nature of the vulnerability in CVE-2025-48868?
CVE-2025-48868 is an authenticated Remote Code Execution vulnerability caused by unsafe use of Python’s eval() function.