Critical severity9.0NVD Advisory· Published Mar 3, 2025· Updated Jun 17, 2026
CVE-2025-27590
CVE-2025-27590
Description
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
oxidized-webRubyGems | < 0.15.0 | 0.15.0 |
Affected products
3cpe:2.3:a:oxidized_web_project:oxidized_web:*:*:*:*:*:oxidized:*:*+ 1 more
- cpe:2.3:a:oxidized_web_project:oxidized_web:*:*:*:*:*:oxidized:*:*range: <0.15.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
4- github.com/ytti/oxidized-web/commit/a5220a0ddc57b85cd122bffee228d3ed4901668envdPatchWEB
- github.com/advisories/GHSA-jx6p-9c26-g373ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-27590ghsaADVISORY
- github.com/ytti/oxidized-web/releases/tag/0.15.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.