SBA Security Advisory – Checkmk Cross Site Scripting (CVE-2025-64999)
Vulnerability Overview
Checkmk in versions before 2.4.0p22 and 2.3.0p43 is prone to a cross-site scripting (XSS) vulnerability when used in a distributed monitoring setup. Any connected remote site can inject JavaScript code in the central site’s user interface.
- Type of Vulnerability: Cross Site Scripting
- Fixed in Version: 2.4.0p22, 2.3.0p43
- CVE ID: CVE-2025-64999
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- CVSS Base Score: 8.4 (High)
Recommended Countermeasure
We recommend updating to Checkmk version 2.4.0p22, 2.3.0p43 or later.
Link
Credits
Lisa Gnedt (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
