Injection Flaw in Checkmk's RestAPI Impacts Livestatus Command Handling
CVE-2025-32918
5.3MEDIUM
What is CVE-2025-32918?
An improper neutralization of command delimiters in the autocomplete endpoint of the RestAPI in Checkmk allows authenticated users to execute arbitrary Livestatus commands. This vulnerability affects specific versions of Checkmk prior to 2.4.0p6, 2.3.0p35, 2.2.0p44, and the end-of-life version 2.1.0, posing a risk to systems relying on this software.
Affected Version(s)
Checkmk 2.4.0 < 2.4.0p6
Checkmk 2.3.0 < 2.3.0p35
Checkmk 2.2.0 < 2.2.0p44