CVE-2025-65100

MEDIUM

Isar 0.11-rc1 and 0.11 - Security Update Bypass via ISAR_APT_SNAPSHOT_DATE

Title source: llm
STIX 2.1

Description

Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distribution, leading to missed security updates. This issue has been patched via commit 738bcbb.

Scores

CVSS v4 6.9
EPSS 0.0032
EPSS Percentile 23.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-693
Status published
Products (1)
ilbers/isar < 738bcbb716c7eb7b34cbb2293cae4f264b3925fe
Published Nov 19, 2025
Tracked Since Feb 18, 2026