OS Command Injection Vulnerability in Mako Server by Mako
CVE-2025-34095
Key Information:
- Vendor
Real Time Logic
- Status
- Vendor
- CVE Published:
- 10 July 2025
Badges
What is CVE-2025-34095?
An OS command injection vulnerability has been identified in Mako Server, specifically within its tutorial interface at the examples/save.lsp endpoint. This flaw allows unauthenticated attackers to execute arbitrary Lua os.execute() commands. By sending a specially crafted PUT request, malicious inputs can be stored on the server. These inputs can later be activated through a GET request to examples/manage.lsp, leading to unauthorized remote command execution on both Windows and Unix-based systems, which poses a significant risk to the integrity and security of the affected deployments.
Affected Version(s)
Mako Server 2.5 <= 2.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
