Understanding CVE-2025-49844: “RediShell” Critical Remote Code Execution in Redis
ID: 024458d5-c748-5080-87a7-9bd7e107fb04
STIX ID: report--024458d5-c748-5080-87a7-9bd7e107fb04
Feed Name: Sysdig Blog
CVE-2025-49844 (RediShell) is a critical (CVSS 10.0) use-after-free vulnerability in Redis Lua scripting that can allow authenticated users to achieve remote code execution and escape the Lua sandbox. The report lists affected Redis OSS/CE/Stack and Enterprise versions, notes that Redis Cloud was auto-patched, describes the exploitation mechanism and potential post-compromise impacts, and provides detection and mitigation guidance including immediate patching, restricting EVAL/EVALSHA via ACLs, disabling Lua if unnecessary, and preventing internet exposure of Redis instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
