CVE-2025-61982

7.8

OpenCFD · OpenFOAM

A code injection vulnerability in the Code Stream directive of OpenCFD OpenFOAM 2506 allows an attacker to achieve arbitrary code execution via a specially crafted simulation file.

Executive summary

An arbitrary code execution vulnerability in OpenCFD OpenFOAM 2506 poses a significant risk to system integrity and security.

Vulnerability

This is a code injection vulnerability (CWE-94) residing within the Code Stream directive functionality. The vulnerability is triggered when an application processes a malicious simulation file, allowing an attacker to execute arbitrary code on the host system.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the user running the simulation. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, and potential lateral movement within the network.

Remediation

Immediate Action: Consult the official OpenCFD vendor advisory for the latest security patches or configuration guidance to disable the vulnerable Code Stream functionality.

Proactive Monitoring: Review system and application logs for suspicious file inputs or unexpected execution patterns originating from OpenFOAM simulation processes.

Compensating Controls: Ensure that OpenFOAM instances are executed within restricted environments or containers with minimal privileges to limit the potential impact of a successful code injection.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized code identified in the provided data.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention to prevent potential system compromise. Administrators should verify their current version of OpenFOAM and prioritize applying vendor-supplied updates or implementing the recommended configuration changes to secure the Code Stream directive.

Sources

Originally found and disclosed by Discovered by Dimitrios Tatsis of Cisco Talos., per the CVE Program record.