PatchSiren cyber security CVE debrief
CVE-2025-58441 KnowageLabs CVE debrief
Knowage, an open-source analytics and business intelligence suite, had a blind server-side request forgery (SSRF) vulnerability prior to version 8.1.37. This vulnerability allowed attackers to send requests to arbitrary hosts or paths but, as the attacker cannot read the response, the impact is limited. However, it can be leveraged to scan the internal network.
- Vendor
- KnowageLabs
- Product
- Knowage-Server
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
Defenders managing Knowage deployments, especially those with untrusted or unauthenticated network access, should assess exposure and prioritize verification and potential remediation.
Why it matters
CVE-2025-58441 is a blind SSRF vulnerability in Knowage that allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance. Defenders should verify exposure, prioritize remediation, and consider compensating controls.
- Network scanning and reconnaissance
- Potential for lateral movement within the network
- Need for compensating controls like network access restrictions
- Verification of deployment versions and exposure
Technical summary
The vulnerability, tracked as CVE-2025-58441, is a blind server-side request forgery (SSRF) issue in Knowage, an open-source analytics and business intelligence suite. Prior to version 8.1.37, the vulnerability allowed attackers to send requests to arbitrary hosts or paths. Although the attacker cannot read the response, limiting the impact, it can be used to scan the internal network. Defenders managing Knowage deployments, especially those with untrusted or unauthenticated network access, should assess exposure and prioritize verification and potential remediation. The vulnerability allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance.
Defensive priority
Defenders should prioritize verifying exposure in their Knowage deployments, especially those with untrusted or unauthenticated network access, and assess the need for compensating controls like network access restrictions or monitoring for suspicious activity.
Recommended defensive actions
- Verify Knowage deployment versions and upgrade to 8.1.37 if vulnerable
- Assess network exposure and restrict access if necessary
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the patched version. A vendor advisory is also available on GitHub. Defenders should verify exposure in their Knowage deployments, especially those with untrusted or unauthenticated network access, and assess the need for compensating controls like network access restrictions or monitoring for suspicious activity. The vulnerability allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-58441 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-58441
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-58441 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58441
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-m6x8-wh9v-6jxp
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.