Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Checkmk Path Traversal (CVE-2025-39664)

Vulnerability Overview

Checkmk in versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b1 is prone to a path traversal vulnerability in the report scheduler. Due to an insufficient validation of a file name input, users can store reports in arbitrary locations on the server.

  • Type of Vulnerability: Path Traversal
  • Fixed in Version: 2.4.0p13, 2.3.0p38, 2.2.0p46
  • CVE ID: CVE-2025-39664
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
  • CVSS Base Score: 7.1 (High)

Recommended Countermeasure

We recommend updating to Checkmk version 2.4.0p13, 2.3.0p38, 2.2.0p46 or later.

Link

Full Security Advisory

Credits

Lisa Gnedt (SBA Research)