CVE-2025-62713

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected. This issue has been fixed in version 3.3.2.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-23 17:15

Updated : 2025-10-23 17:15


NVD link : CVE-2025-62713

Mitre link : CVE-2025-62713

CVE.ORG link : CVE-2025-62713


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-284

Improper Access Control