CVE-2025-50900
9.8getrebuild · rebuild
A critical security vulnerability exists in the Rebuild application within the RebuildWebInterceptor class, potentially allowing unauthenticated remote execution.
Executive summary
A critical, potentially unauthenticated remote code execution vulnerability has been identified in the getrebuild/rebuild application.
Vulnerability
The vulnerability exists in the com.rebuild.web.RebuildWebInterceptor class, specifically within the preHandle function. It involves improper handling of input, likely related to codec utility processing, which can be leveraged by an unauthenticated attacker.
Business impact
With a CVSS score of 9.8, this vulnerability allows for complete system compromise. Successful exploitation likely leads to full unauthorized access to the underlying server, data exfiltration, and potential for further lateral movement within the network.
Remediation
Immediate Action: Review the vendor advisory provided by the developers of Rebuild to identify the specific patched version and apply the update immediately.
Proactive Monitoring: Monitor for unusual traffic patterns targeting the Rebuild web application and review logs for suspicious function calls associated with the RebuildWebInterceptor class.
Compensating Controls: Place the affected instance behind a WAF and enforce strict IP allow-listing to mitigate the risk of unauthorized external access while a patch is being deployed.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total system compromise, immediate attention is required. Organizations should prioritize identifying their current version of Rebuild and applying the necessary security updates provided by the vendor as soon as they become available.