Shell Command Execution Vulnerability in ClickHouse by Altinity
CVE-2025-52969
What is CVE-2025-52969?
In ClickHouse version 25.7.1.557, a vulnerability allows low-privileged users to execute shell commands by querying Executable() tables established by higher-privileged users. Although the system restricts the CREATE TABLE permission, it lacks proper access control measures to prevent low-privileged users from accessing existing Executable tables. If an attacker can modify the script associated with the Executable() engine via writable paths, they could run malicious commands in the context of the ClickHouse server, leading to potential privilege escalation and unauthorized execution of code. The vendor suggests that such command executions by low-privileged users are expected behavior.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ClickHouse 25.7.1.557
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
