← back
CVE-2025-8868criticalobserved exploitationCWE-200CWE-89

Chef Automate compliance service SQL Injection Vulnerability

70Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 24%
from disclosure to weapon
Published on NVDSep 29
VulnCheck+17d
exploitation probability
24%top 2% of all CVEs
observed exploitation
yesVulnCheck
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H