When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to specific directories, a misconfigured server can be exploited by an attacker with privilege to access to both table engines to execute arbitrary code on the ClickHouse server. You can check if your ClickHouse server is vulnerable to this vulnerability by inspecting the configuration file and confirming if the following setting is enabled: <library_bridge> <port>9019</port> </library_bridge>
Conclusion & alert: CVE-2025-1385 is rated Moderate Risk (41.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-28 | 0.19% | 0.13% | -0.06% |
| 2 | 2025-11-21 | 0.42% | 0.19% | -0.23% |
| 3 | 2025-11-18 | — | 0.42% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 4.0 | HIGH |
|
— | — | cb7ba516-3b07-4c98-b0c2-715220f1a8f6 |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2025-1385 unimportant priority: Debian including 1 source packages (clickhouse), 2 status rows across 2 suites (bookworm, bullseye): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2025-1385 |
ubuntu
|
medium | CVE-2025-1385 medium priority: Ubuntu including 1 source packages (clickhouse), 7 status rows across 7 suites (focal, jammy, noble, oracular, plucky, questing, upstream): DNE 4, needs-triage 3. | https://ubuntu.com/security/CVE-2025-1385 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||