CVE-2025-30055: Cgm Clininet

Critical severity, CVSS 9.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.

Affected products

  • Cgm Cgm Clininet: before 2024.MS4 (fixed in 2024.MS4)

Published 2025-08-27. Last modified 2026-06-17.