CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability
Record summary
CVE-2025-8868 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 16, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 4.13.295 | affected |
automateBrowse chef / automate | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALChef Automate < 4.13.295 — SQL InjectionCVSS 9.8
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
Impact
Authenticated attackers with knowledge of a well-known token can execute arbitrary SQL queries through the compliance service, potentially gaining access to restricted functionality and sensitive data.
Remediation
Upgrade to version 4.13.295 or later.
Source: ProjectDiscovery