CVE-2024-25294: Getrebuild Rebuild

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.

Affected products

Published 2024-03-20. Last modified 2026-07-09.