HIGH7.5
GHSA-wp68-xrfg-xvq4
Cockpit Arbitrary File Upload
Quick fix
GHSA-wp68-xrfg-xvq4 — cockpit-hq/cockpit: upgrade to the fixed version with the command below.
composer require cockpit-hq/cockpit:^2.4.1Details
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cockpit-hq/cockpit
Introduced in:
0Fixed in: 2.4.1Fix
composer require cockpit-hq/cockpit:^2.4.1References
- https://nvd.nist.gov/vuln/detail/CVE-2025-1025[ADVISORY]
- https://github.com/Cockpit-HQ/Cockpit/commit/984ef9ad270357b843af63c81db95178eae42cae[WEB]
- https://github.com/Cockpit-HQ/Cockpit/commit/becca806c7071ecc732521bb5ad0bb9c64299592[WEB]
- https://gist.github.com/CHOOCS/fe1227443544d5d74c33982814f290af[WEB]
- https://github.com/Cockpit-HQ/Cockpit[PACKAGE]
- https://security.snyk.io/vuln/SNYK-PHP-COCKPITHQCOCKPIT-8516320[WEB]