RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score
ID: d1e998c3-19ce-55be-920b-e917edadd199
STIX ID: report--d1e998c3-19ce-55be-920b-e917edadd199
Feed Name: Wiz Blog
Threat Score
**RediShell (CVE-2025-49844)** disclosed by Wiz Research is a critical CVSS 10.0 Remote Code Execution vulnerability in Redis that allows a post-auth attacker to escape the Lua sandbox via a Use-After-Free and execute arbitrary native code on the host; it affects Redis forks and managed services, with the report noting ~330,000 internet-exposed instances and ~60,000 unauthenticated instances, and urges immediate patching and hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
