Unrated severityNVD Advisory· Published Sep 17, 2025· Updated Sep 30, 2025
CISA Thorium LDAP injection
CVE-2025-35431
Description
CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.
Affected products
2- CISA/Thoriumv5Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.