PT-2025-9850 · Volt · Volt

·

CVE-2025-27517

·

Published

2025-03-05

·

Updated

2025-05-11

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Volt versions prior to 1.7.0
Description The issue concerns a remote code execution vulnerability within Volt components. Malicious, user-crafted request payloads could potentially lead to remote code execution. Approximately 1.08 million downloads are at risk.
Recommendations To resolve the issue, upgrade to version 1.7.0 or later. As a temporary workaround, consider restricting access to vulnerable components until a patch is applied. Avoid using malicious or user-crafted request payloads in the affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27517
GHSA-V69F-5JXM-HWVV

Affected Products

Volt