Unrated severityNVD Advisory· Published Oct 9, 2025· Updated Nov 3, 2025
Path-Traversal in report scheduler
CVE-2025-39664
Description
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- checkmk.com/werk/17984mitrevendor-advisory
- github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20250730-01_Checkmk_Path_Traversalmitrethird-party-advisory
News mentions
0No linked articles in our index yet.