CVE Database
/

CVE-2025-32918

Back to search

CVE-2025-32918

Published: Jul 4, 2025

Modified: Jul 8, 2025

PUBLISHED

Description

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

VendorProductVersions

Checkmk GmbH

Checkmk

affected
2.4.0 - < 2.4.0p6
affected
2.3.0 - < 2.3.0p35
affected
2.2.0 - < 2.2.0p44
affected
2.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now