CVE-2025-1686
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Feb 27, 2025
CWE ID 73
Summary
CVE-2025-1686 is a vulnerability affecting all versions of the io.pebbletemplates:pebble package. This issue permits an attacker, with high privileges, to control the file name or path through the 'include' tag in malicious notification templates. By doing so, they can gain access to sensitive local files, including /etc/passwd and /proc/1/environ. The risk can be mitigated by disabling the 'include' macro in Pebble Templates using the provided Java code snippet.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.