CVEs/Disclosures


CVEs/Publications

In no particular order, and likely incomplete...

React.js (and Next.js)

  • "React2Shell" CVE-2025-55182/CVE-2025-66478 - Unauthenticated RCE in React Server Components

Aerohive/Extreme Networks

Magento

CryptPad

  • CVE-2025-49591 - Multi-Factor Authentication bypass, via public key format confusion
  • CVE-2025-49590 - DOM XSS vector, via URI protocol confusion to circumvent javascript: filters

https://blog.cryptpad.org/2025/06/18/2024.12.0-security-issues/

InterWorx Hosting Platform (NodeWorx/SiteWorx)

(never officially published - lack of communication from security team after updates were applied)

  • Critical unauthenticated root RCE, via very low entropy in system API key generation used to create root cronjob
  • Low-priv hosting customer to root privesc, via very low entropy MySQL root password, used to create root cronjob