GHSA-4v9x-cqc5-j645 · Severity: critical · Ecosystem: pip — Codechecker has an authentication bypass for certain API calls
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3.
Conclusion & alert: CVE-2026-25660 is rated Moderate Risk (49/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.41%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.03% | 0.41% | +0.39% |
| 2 | 2026-05-22 | 0.05% | 0.03% | -0.03% |
| 3 | 2026-04-25 | — | 0.05% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | 85b1779b-6ecd-4f52-bcc5-73eac4659dcf |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-4v9x-cqc5-j645 · Severity: critical · Ecosystem: pip — Codechecker has an authentication bypass for certain API calls
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ericsson | codechecker | < 6.27.4 | cpe:2.3:a:ericsson:codechecker:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Ericsson/codechecker/security/advisories/GHSA-4v9x-cqc5-j645 | Vendor Advisory |