CVE-2025-48740: Strangebee Thehive

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user, authenticated with basic authentication.

Affected products

  • Strangebee Thehive: from 5.2.0, before 5.2.16 (fixed in 5.2.16); from 5.3.0, before 5.3.11 (fixed in 5.3.11); from 5.4.0, before 5.4.10 (fixed in 5.4.10); from 5.5.0, before 5.5.1 (fixed in 5.5.1)

Published 2025-05-23. Last modified 2026-06-17.