Remote Code Execution Vulnerability in FACTION PenTesting Framework
CVE-2025-66022

9.7CRITICAL

Key Information:

Status
Vendor
CVE Published:
26 November 2025

What is CVE-2025-66022?

FACTION, a framework for PenTesting report generation and collaboration, has a vulnerability that allows untrusted extension code to execute arbitrary system commands on the host server. This is facilitated through an insecure extension management interface that does not require authentication, enabling unauthenticated attackers to inject malicious extensions and gain control over the server. This severe security flaw is present in versions prior to 1.7.1 and has been addressed in the latest release.

Affected Version(s)

faction < 1.7.1

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.