Remote Code Execution Vulnerability in FACTION PenTesting Framework
CVE-2025-66022
9.7CRITICAL
What is CVE-2025-66022?
FACTION, a framework for PenTesting report generation and collaboration, has a vulnerability that allows untrusted extension code to execute arbitrary system commands on the host server. This is facilitated through an insecure extension management interface that does not require authentication, enabling unauthenticated attackers to inject malicious extensions and gain control over the server. This severe security flaw is present in versions prior to 1.7.1 and has been addressed in the latest release.
Affected Version(s)
faction < 1.7.1
