CVE-2024-28125: Fitnesse

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.

Affected products

Published 2024-03-18. Last modified 2026-06-17.