CVE-2025-8868
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
9.8
CVSS
24.3%
EPSS (exploit prob.)
98th
EPSS percentile
2025-09-29
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| chef | automate | < 4.13.295 |
| chef | automate | >= 20180319150121, <= 20220329091442 |
| linux | linux_kernel | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-8868