Unrestricted Project Deletion Vulnerability in reNgine by Yogesh Ojha
CVE-2025-24968
What is CVE-2025-24968?
The reNgine framework for automated web application reconnaissance contains a vulnerability that allows users with limited roles, such as 'penetration_tester' or 'auditor', to delete all projects within the system. This severe flaw can facilitate a complete takeover of the system as it exposes users to unauthorized access, potentially redirecting attackers to the onboarding interface. In this compromised state, attackers may add or alter user roles, including that of System Administrators, and manipulate crucial configurations like API keys and user preferences. This vulnerability affects all versions of reNgine up to and including 2.20, and users are strongly recommended to stay vigilant for updates that will address this security issue. Currently, there are no workarounds available.
Affected Version(s)
rengine <= 2.2.0