CVE-2025-49537: ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by a high-privileged attacker. Exploitation of this issue requires user interaction and scope is changed. The vulnerable component is restricted to internal IP addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49537?
CVE-2025-49537 has a high severity rating as it allows high-privileged attackers to execute arbitrary code.
How do I fix CVE-2025-49537?
To fix CVE-2025-49537, upgrade to a version of Adobe ColdFusion later than 2025.2, 2023.14, or 2021.20.
What versions of ColdFusion are affected by CVE-2025-49537?
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by CVE-2025-49537.
What type of vulnerability is CVE-2025-49537?
CVE-2025-49537 is an OS Command Injection vulnerability that results from improper neutralization of special elements.
Who is primarily at risk from CVE-2025-49537?
High-privileged attackers are primarily at risk from exploiting CVE-2025-49537 to execute arbitrary code.