CVE-2025-66022: FACTION Unauthenticated Custom Extension Upload leads to RCE
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the server when a lifecycle hook is invoked, resulting in remote code execution (RCE) on the host running Faction. Due to a missing authentication check on the /portal/AppStoreDashboard endpoint, an attacker can access the extension management UI and upload a malicious extension without any authentication, making this vulnerability exploitable by unauthenticated users. This issue has been patched in version 1.7.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66022?
CVE-2025-66022 is considered a critical vulnerability due to its potential to allow untrusted code execution on the server.
How do I fix CVE-2025-66022?
To mitigate CVE-2025-66022, upgrade FACTION to version 1.7.1 or later.
What impact does CVE-2025-66022 have on affected systems?
CVE-2025-66022 can lead to unauthorized execution of arbitrary system commands, compromising the security of the server.
Which versions of FACTION are affected by CVE-2025-66022?
FACTION versions prior to 1.7.1 are affected by CVE-2025-66022.
Who is affected by CVE-2025-66022?
Any user or organization running FACTION versions before 1.7.1 is at risk due to CVE-2025-66022.