CVE-2025-13957

HIGH

SOCKS Proxy - Info Disclosure & RCE

Title source: llm
STIX 2.1

Description

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

Scores

CVSS v4 7.5
EPSS 0.0049
EPSS Percentile 65.4%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Published Mar 10, 2026
Tracked Since Mar 11, 2026