CVE-2025-53899

Source
https://cve.org/CVERecord?id=CVE-2025-53899
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53899.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-53899
Aliases
  • GHSA-5gx5-vcpp-8cr5
Published
2025-11-29T02:25:23.493Z
Modified
2026-03-13T03:32:06.382143Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Kiteworks MFT is vulnerable to an Incorrectly Specified Destination in a Communication Channel
Details

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53899.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-941"
    ]
}
References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "9.1.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-53899.json"