File Loading Vulnerability in NXLog Agent by NXLog
CVE-2025-67900

8.1HIGH

Key Information:

Vendor

Nxlog

Vendor
CVE Published:
14 December 2025

What is CVE-2025-67900?

The NXLog Agent, prior to version 6.11, presents a file loading vulnerability that can be exploited via the OPENSSL_CONF environment variable. This issue may allow attackers to load arbitrary files, potentially leading to unauthorized data access or manipulation. Organizations using the affected versions are urged to upgrade to the latest release to mitigate this risk.

Affected Version(s)

NXLog Agent 0 < 6.11

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67900 : File Loading Vulnerability in NXLog Agent by NXLog