CVE-2025-1686

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Feb 27, 2025
CWE ID 73

Summary

CVE-2025-1686 is a vulnerability affecting all versions of the io.pebbletemplates:pebble package. This issue permits an attacker, with high privileges, to control the file name or path through the 'include' tag in malicious notification templates. By doing so, they can gain access to sensitive local files, including /etc/passwd and /proc/1/environ. The risk can be mitigated by disabling the 'include' macro in Pebble Templates using the provided Java code snippet.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share