CVE-2025-66022 is a critical remote code execution (RCE) vulnerability affecting OWASP Faction, a PenTesting Report Generation and Collaboration Framework, in versions prior to 1.7.1. This flaw allows unauthenticated attackers to upload malicious extensions via a missing authentication check on the /portal/AppStoreDashboard endpoint. Once uploaded, the untrusted extension code can execute arbitrary system commands on the server when a lifecycle hook is invoked. The vulnerability carries a CVSS score of 9.8 (Critical), indicating a severe risk due to its network-based attack vector, low attack complexity, and no required user interaction or privileges. Successful exploitation leads to complete compromise of confidentiality, integrity, and availability of the host running Faction. Currently, there is no known active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable. While community discussion is minimal, the critical nature of this vulnerability necessitates immediate patching to version 1.7.1 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.1CPE matchmatch criteria | cpe:2.3:a:owasp:faction:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.