CVE-2025-20233: Splunk App For Lookup File Editing

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

Affected products

  • Splunk Splunk App For Lookup File Editing: from 4.0.0, before 4.0.5 (fixed in 4.0.5)

Published 2025-03-26. Last modified 2026-06-17.