Record summary

CVE-2025-8868 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 16, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Chef Automate

Browse Progress Software / Chef Automatecompliance service

Default status: unaffected

CVE ListBefore 4.13.295affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALChef Automate < 4.13.295 — SQL InjectionCVSS 9.8

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

Impact

Authenticated attackers with knowledge of a well-known token can execute arbitrary SQL queries through the compliance service, potentially gaining access to restricted functionality and sensitive data.

Remediation

Upgrade to version 4.13.295 or later.

WeaknessesCWE-89
Authors3th1c_yuk1, xbow
Template tagscvecve2025chefautomatesqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
FOFA: body="Chef Automate"

Source: ProjectDiscovery

References

2