Unrestricted Project Deletion Vulnerability in reNgine by Yogesh Ojha
CVE-2025-24968
What is CVE-2025-24968?
The reNgine framework for automated web application reconnaissance contains a vulnerability that allows users with limited roles, such as 'penetration_tester' or 'auditor', to delete all projects within the system. This severe flaw can facilitate a complete takeover of the system as it exposes users to unauthorized access, potentially redirecting attackers to the onboarding interface. In this compromised state, attackers may add or alter user roles, including that of System Administrators, and manipulate crucial configurations like API keys and user preferences. This vulnerability affects all versions of reNgine up to and including 2.20, and users are strongly recommended to stay vigilant for updates that will address this security issue. Currently, there are no workarounds available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
rengine <= 2.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
