CVE-2025-50900

9.8

getrebuild · rebuild

A critical security vulnerability exists in the Rebuild application within the RebuildWebInterceptor class, potentially allowing unauthenticated remote execution.

Executive summary

A critical, potentially unauthenticated remote code execution vulnerability has been identified in the getrebuild/rebuild application.

Vulnerability

The vulnerability exists in the com.rebuild.web.RebuildWebInterceptor class, specifically within the preHandle function. It involves improper handling of input, likely related to codec utility processing, which can be leveraged by an unauthenticated attacker.

Business impact

With a CVSS score of 9.8, this vulnerability allows for complete system compromise. Successful exploitation likely leads to full unauthorized access to the underlying server, data exfiltration, and potential for further lateral movement within the network.

Remediation

Immediate Action: Review the vendor advisory provided by the developers of Rebuild to identify the specific patched version and apply the update immediately.

Proactive Monitoring: Monitor for unusual traffic patterns targeting the Rebuild web application and review logs for suspicious function calls associated with the RebuildWebInterceptor class.

Compensating Controls: Place the affected instance behind a WAF and enforce strict IP allow-listing to mitigate the risk of unauthorized external access while a patch is being deployed.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for total system compromise, immediate attention is required. Organizations should prioritize identifying their current version of Rebuild and applying the necessary security updates provided by the vendor as soon as they become available.