OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/cor
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates t
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_m
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ
Frequently Asked Questions
What is CWE-625?
CWE-625 (CWE-625) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-625?
There are 11 CVE records associated with CWE-625 in our database. Of these, 2 are critical severity, 2 are high severity, and 7 are medium severity.
How can I protect against CWE-625 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-625 using AI-powered security agents.
Detect CWE-625 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-625 vulnerabilities across your infrastructure.
Get Started