CVE-2025-62713
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-23
Last updated on: 2025-10-27
Assigner: GitHub, Inc.
Description
Description
Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected. This issue has been fixed in version 3.3.2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kottster | cli | 3.2.0 |
| kottster | server | 3.3.2 |
| kottster | server | 3.2.0 |
| kottster | cli | 3.3.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |