Insufficient Escaping Vulnerability in Checkmk Reporting Tool
CVE-2025-39664
7.1HIGH
What is CVE-2025-39664?
The Checkmk reporting tool contains a vulnerability due to insufficient escaping in the report scheduler. This flaw allows authenticated attackers to manipulate the storage location of report file pairs, potentially leading them to store files outside the designated root directory, which can compromise data security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Checkmk 2.4.0 < 2.4.0p13
Checkmk 2.3.0 < 2.3.0p38
Checkmk 2.2.0 < 2.2.0p46
