CVE-2018-5225: Atlassian Bitbucket

Critical severity, CVSS 9.9. EPSS: 3.4% chance of exploitation in the next 30 days.

In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.

Affected products

  • Atlassian Bitbucket: from 4.13.0, before 5.4.8 (fixed in 5.4.8); after 5.5.0, before 5.5.8 (fixed in 5.5.8); from 5.6.0, before 5.6.5 (fixed in 5.6.5); from 5.7.0, before 5.7.3 (fixed in 5.7.3); from 5.8.0, before 5.8.2 (fixed in 5.8.2)

Published 2018-03-22. Last modified 2026-06-17.