Description

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email. This vulnerability is fixed in 1.33.0.

INFO

Published Date :

2025-01-27T17:46:15.260Z

Last Modified :

2025-02-12T20:41:36.200Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-24364 vulnerability.

Vendors Products
Dani-garcia
  • Vaultwarden
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-24364.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact