CVE-2025-11240: Knime Business Hub

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. This might open the possibility for fishing or other similar attacks. The problem has been fixed in KNIME Business Hub 1.16.0.

Affected products

  • Knime Business Hub: before 1.16.0 (fixed in 1.16.0)

Published 2025-10-02. Last modified 2026-06-17.