logo

Critical Remote Code Execution Vulnerability in GitBucket Disclosed

ID: 4f333c18-0f34-5c4b-905f-b73aeb97cc6b

STIX ID: report--4f333c18-0f34-5c4b-905f-b73aeb97cc6b

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-05-17

Date Updated: 2026-05-18

...
...

Critical remote code execution vulnerability (CVE-2018-25332) affects GitBucket 4.23.1: attackers can exploit weak secret token generation and insecure file upload via the git-lfs endpoint to brute-force a Blowfish key, upload malicious JAR plugins, and execute arbitrary commands; validated by three independent sources and disclosed May 17, 2026 — affected organizations should assess and remediate vulnerable instances immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.