CVE-2025-2887

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 352

Summary

CVE-2025-2887 is a vulnerability affecting a specific client that fails to detect rollbacks during delegated target operations. This issue could result in the client fetching target contents from an incorrect source, leading to potential alterations. To mitigate this risk, users are advised to upgrade to version 0.20.0 or later of the affected software and ensure any forked or derivative codes are patched with the latest fixes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share