CVE-2024-28125: Fitnesse
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.
Affected products
Published 2024-03-18. Last modified 2026-06-17.