Improper Input Validation in Kafka UI by Provectus
CVE-2025-60537
6.5MEDIUM
What is CVE-2025-60537?
A security flaw exists in the Kafka UI application developed by Provectus due to improper input validation in the Java component CustomSerdeLoader.java. This vulnerability enables attackers to execute arbitrary code by supplying specially crafted data to the application. Affected versions span from 0.6.0 to 0.7.2, highlighting a critical need for users to update to secure versions to mitigate the risk of exploitation.
