SBA Security Advisory – Checkmk Path Traversal (CVE-2025-39664)
Vulnerability Overview
Checkmk in versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b1 is prone to a path traversal vulnerability in the report scheduler. Due to an insufficient validation of a file name input, users can store reports in arbitrary locations on the server.
- Type of Vulnerability: Path Traversal
- Fixed in Version: 2.4.0p13, 2.3.0p38, 2.2.0p46
- CVE ID: CVE-2025-39664
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- CVSS Base Score: 7.1 (High)
Recommended Countermeasure
We recommend updating to Checkmk version 2.4.0p13, 2.3.0p38, 2.2.0p46 or later.
Link
Credits
Lisa Gnedt (SBA Research)