CVE-2025-66377: High severity Pexip Infinity vulnerability
Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operation of other nodes within the installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pexip Infinityto a version that resolves this vulnerability.Fixed in 39.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66377?
CVE-2025-66377 is considered critical due to the potential impact on the operation of other nodes in a Pexip Infinity installation.
How do I fix CVE-2025-66377?
To fix CVE-2025-66377, update Pexip Infinity to version 39.0 or later.
Who is affected by CVE-2025-66377?
Any user running Pexip Infinity versions prior to 39.0 is affected by CVE-2025-66377.
What does CVE-2025-66377 allow an attacker to do?
CVE-2025-66377 allows an attacker to impact the operation of other nodes within a Pexip Infinity installation if they have access to execute code on one node.
What type of vulnerability is CVE-2025-66377?
CVE-2025-66377 is classified as a missing authentication vulnerability for a critical function within a product-internal API.