CVE-2025-46067
8.2Automai · Director
Automai Director v25.2.0 is vulnerable to privilege escalation and sensitive information disclosure via a crafted JavaScript file, allowing unauthenticated remote access.
Executive summary
A critical vulnerability in Automai Director allows unauthenticated remote attackers to escalate privileges and access sensitive data, representing a high risk to system integrity.
Vulnerability
The vulnerability allows an unauthenticated remote attacker to manipulate the system by uploading or utilizing a crafted JavaScript file, which triggers unauthorized privilege escalation and information disclosure.
Business impact
The exploitation of this flaw could lead to a complete compromise of administrative accounts and the exfiltration of sensitive organizational data. Given the CVSS score of 8.2, this vulnerability is classified as High severity, indicating that the potential for unauthorized access to critical business systems is significant and requires immediate attention to prevent operational disruption.
Remediation
Immediate Action: Contact Automai support or monitor the official vendor website to obtain and apply the necessary security patch for version 25.2.0 as soon as it is released.
Proactive Monitoring: Review web server and application access logs for irregular file requests or unexpected JavaScript execution patterns that could indicate malicious activity.
Compensating Controls: Deploy a Web Application Firewall to block suspicious file uploads and restrict access to the Director administrative interface to authorized IP addresses only.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists via the GitHub Gist referenced in the vulnerability documentation.
Analyst recommendation
Due to the high severity of this privilege escalation flaw and the availability of a public proof-of-concept, organizations must prioritize the hardening of their Automai Director deployments. Administrators should restrict network exposure immediately and prepare to apply the vendor-supplied patch the moment it becomes available to ensure the security of their environment.
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Analyst report written