GHSA-c8g6-qrwh-m3vp · Severity: critical · Ecosystem: go — NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT to generate a command to be executed via popen, without first sanitising their values. The entry process of the enforcer container is the monitor process. When the enforcer container stops, the monitor process checks whether the consul subprocess has exited. To perform this check, the monitor process uses the popen function to execute a shell command that determines whether the ports used by the consul subprocess are still active. The values of environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PORT are used directly to compose shell commands via popen without validation or sanitization. This behavior could allow a malicious user to inject malicious commands through these variables within the enforcer container.
Conclusion & alert: CVE-2025-54469 is rated Moderate Risk (45.6/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-25 | 0.04% | 0.06% | +0.01% |
| 2 | 2026-05-22 | 0.06% | 0.04% | -0.01% |
| 3 | 2026-04-09 | — | 0.06% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
GHSA-c8g6-qrwh-m3vp · Severity: critical · Ecosystem: go — NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
critical | CVE-2025-54469 severity critical: SUSE including 1 source package names (govulncheck-vulndb-0.0.20251105T184115-1.1), 1 product×package rows across 1 product lines (openSUSE Tumbleweed): Fixed 1. | https://www.suse.com/security/cve/CVE-2025-54469/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||