cbcvebase.
CVE-2025-41717
published 2026-01-13

CVE-2025-41717: An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code…

PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.50%
39.2th percentile
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Injection’).

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
msrcazl3_gcc_13.2.0-7
msrcazl3_golang_1.17.13-2_1.18.8-2_1.21.6-1
msrcazl3_golang_1.24.3-1
msrcazl3_moby-engine_20.10.25-3
msrcazl3_moby-engine_25.0.3-1
msrcazl3_prometheus_2.37.0-11
msrcazl3_prometheus_2.45.4-1
msrcazl3_python-tensorboard_2.16.2-6
msrcazl3_sriov-network-device-plugin_3.5.1-3
msrcazl3_sriov-network-device-plugin_3.7.0-1
msrcazl3_tensorflow_2.16.1-9
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_azcopy_10.15.0-15
msrccbl2_azcopy_10.24.0-1
msrccbl2_containerized-data-importer_1.55.0-20
msrccbl2_containerized-data-importer_1.55.0-23
msrccbl2_cri-o_1.21.7-3
msrccbl2_csi-driver-lvm_0.4.1-17
msrccbl2_gh_2.13.0-2
msrccbl2_golang_1.17.13-2
msrccbl2_golang_1.18.8-7
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.