CVE-2025-39664: Checkmk
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.
Affected products
- Checkmk Checkmk: from 2.1.0, before 2.2.0 (fixed in 2.2.0); version 2.2.0 only; version 2.3.0 only; version 2.4.0 only
Published 2025-10-09. Last modified 2026-06-17.