PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-58441 KnowageLabs CVE debrief

Knowage, an open-source analytics and business intelligence suite, had a blind server-side request forgery (SSRF) vulnerability prior to version 8.1.37. This vulnerability allowed attackers to send requests to arbitrary hosts or paths but, as the attacker cannot read the response, the impact is limited. However, it can be leveraged to scan the internal network.

Vendor
KnowageLabs
Product
Knowage-Server
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders managing Knowage deployments, especially those with untrusted or unauthenticated network access, should assess exposure and prioritize verification and potential remediation.

Why it matters

CVE-2025-58441 is a blind SSRF vulnerability in Knowage that allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance. Defenders should verify exposure, prioritize remediation, and consider compensating controls.

  • Network scanning and reconnaissance
  • Potential for lateral movement within the network
  • Need for compensating controls like network access restrictions
  • Verification of deployment versions and exposure

Technical summary

The vulnerability, tracked as CVE-2025-58441, is a blind server-side request forgery (SSRF) issue in Knowage, an open-source analytics and business intelligence suite. Prior to version 8.1.37, the vulnerability allowed attackers to send requests to arbitrary hosts or paths. Although the attacker cannot read the response, limiting the impact, it can be used to scan the internal network. Defenders managing Knowage deployments, especially those with untrusted or unauthenticated network access, should assess exposure and prioritize verification and potential remediation. The vulnerability allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance.

Defensive priority

Defenders should prioritize verifying exposure in their Knowage deployments, especially those with untrusted or unauthenticated network access, and assess the need for compensating controls like network access restrictions or monitoring for suspicious activity.

Recommended defensive actions

  • Verify Knowage deployment versions and upgrade to 8.1.37 if vulnerable
  • Assess network exposure and restrict access if necessary
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the patched version. A vendor advisory is also available on GitHub. Defenders should verify exposure in their Knowage deployments, especially those with untrusted or unauthenticated network access, and assess the need for compensating controls like network access restrictions or monitoring for suspicious activity. The vulnerability allows attackers to send requests to arbitrary hosts or paths, which can be used for network scanning and reconnaissance.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-58441 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-58441

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-58441 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58441

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/KnowageLabs/Knowage-Server/security/advisories/GHSA-m6x8-wh9v-6jxp

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.