CVE-2025-61301
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-20

Last updated on: 2025-10-21

Assigner: MITRE

Description
Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits or orjson recursion errors when the sample executes in the sandbox.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-20
Last Modified
2025-10-21
Generated
2026-06-16
AI Q&A
2025-10-21
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
cape capev2 *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-analysis issue in CAPEv2's reporting modules (reporting/mongodb.py and reporting/jsondump.py). Attackers who can submit samples can cause the behavioral analysis reports to be incomplete or missing by submitting samples that generate deeply nested or oversized behavior data. This triggers MongoDB BSON limits or orjson recursion errors during sandbox execution, preventing proper analysis reporting.

Impact Analysis

The vulnerability can impact you by causing incomplete or missing behavioral analysis reports when running samples in the CAPEv2 sandbox. This means that malicious behavior might not be fully captured or reported, reducing the effectiveness of malware analysis and potentially allowing threats to go undetected.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-61301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart