github.com/lf-edge/ekuiper/v2
Lightweight data stream processing engine for IoT edge
Activity
- Latest release
- 5d ago
- Total releases
- 57
- Cadence
- ~13 days
- Last 12 months
- 21
Reach
- Stars
- 1.7k
Details
- First release
- Apr 19, 2024
| Version | Released | |
|---|---|---|
v2.4.2
patch
|
v2.4.2
patch
Dependencies (110)
+ 102 more |
|
v2.5.0-alpha.1
pre
|
v2.5.0-alpha.1
pre
Dependencies (111)
+ 103 more |
|
v2.4.1
patch
|
v2.4.1
patch
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.10
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.10
pre
Dependencies (109)
+ 101 more |
|
v2.4.0
minor
1 CVE
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0
minor
Dependencies (109)
+ 101 more |
|
v2.4.0-beta.9
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.9
pre
Dependencies (109)
+ 101 more |
|
v2.4.0-beta.8
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.8
pre
Dependencies (109)
+ 101 more |
|
v2.4.0-beta.7
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.7
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.6
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.6
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.5
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.5
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.4
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.4
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.3
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.3
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.2
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.2
pre
Dependencies (110)
+ 102 more |
|
v2.4.0-beta.1
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-beta.1
pre
Dependencies (109)
+ 101 more |
|
v2.4.0-alpha.3
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-alpha.3
pre
Dependencies (109)
+ 101 more |
|
v2.4.0-alpha.2
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-alpha.2
pre
Dependencies (109)
+ 101 more |
|
v2.3.1
minor
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.3.1
minor
Dependencies (108)
+ 100 more |
|
v2.4.0-alpha.1
pre
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.4.0-alpha.1
pre
Dependencies (109)
+ 101 more |
|
v2.3.0
minor
3 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (108)
+ 100 more |
|
v2.3.0-beta.7
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.7
pre
Dependencies (108)
+ 100 more |
|
v2.3.0-beta.6
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.6
pre
Dependencies (108)
+ 100 more |
|
v2.3.0-beta.5
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.5
pre
Dependencies (107)
+ 99 more |
|
v2.2.3
patch
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.3
patch
Dependencies (107)
+ 99 more |
|
v2.3.0-beta.4
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.4
pre
Dependencies (107)
+ 99 more |
|
v2.2.2
patch
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.2
patch
Dependencies (107)
+ 99 more |
|
v2.3.0-beta.2
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.2
pre
Dependencies (107)
+ 99 more |
|
v2.3.0-beta.1
pre
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.3.0-beta.1
pre
Dependencies (107)
+ 99 more |
|
v2.2.1
minor
4 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.1
minor
Dependencies (107)
+ 99 more |
|
v2.1.5
patch
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.5
patch
Dependencies (106)
+ 98 more |
|
v2.2.0-alpha.5
pre
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.0-alpha.5
pre
Dependencies (107)
+ 99 more |
|
v2.1.4
patch
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.4
patch
Dependencies (106)
+ 98 more |
|
v2.2.0-alpha.4
pre
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.0-alpha.4
pre
Dependencies (107)
+ 99 more |
|
v2.1.4-beta.1
pre
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.4-beta.1
pre
Dependencies (106)
+ 98 more |
|
v2.1.3
patch
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.3
patch
Dependencies (106)
+ 98 more |
|
v2.2.0-alpha.3
pre
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.2.0-alpha.3
pre
Dependencies (107)
+ 99 more |
|
v2.1.1
patch
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (106)
+ 98 more |
|
v2.1.0
minor
7 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (106)
+ 98 more |
|
v2.0.8
patch
8 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.8
patch
Dependencies (101)
+ 93 more |
|
v2.1.0-beta.4
pre
8 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0-beta.4
pre
Dependencies (106)
+ 98 more |
|
v2.1.0-beta.2
pre
8 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0-beta.2
pre
Dependencies (106)
+ 98 more |
|
v2.1.0-beta.1
pre
8 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0-beta.1
pre
Dependencies (107)
+ 99 more |
|
v2.0.6
patch
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.6
patch
Dependencies (101)
+ 93 more |
|
v2.0.5
patch
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.5
patch
Dependencies (101)
+ 93 more |
|
v2.1.0-alpha.1
pre
8 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev |
v2.1.0-alpha.1
pre
Dependencies (103)
+ 95 more |
|
v2.0.1
patch
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (101)
+ 93 more |
|
v2.0.0
initial
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (101)
+ 93 more |
|
v2.0.0-beta.2
pre
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.0-beta.2
pre
Dependencies (101)
+ 93 more |
|
v2.0.0-beta.1
pre
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.0-beta.1
pre
Dependencies (70)
+ 62 more |
|
v2.0.0-alpha.11
pre
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.0-alpha.11
pre
Dependencies (68)
+ 60 more |
|
v2.0.0-alpha.9
pre
9 CVEs
CVE-2025-58363
GHSA-c23q-fw86-9h5x
Sep 09, 2026
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
Low
High
SummaryA path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. DetailsIn A related issue in configuration and rule lifecycle management where unvalidated rule identifiers could influence file deletion paths was also addressed by introducing unified identifier and file name validation. PoC
ImpactAn attacker with access to eKuiper management APIs can cause arbitrary file or directory deletion, potentially leading to denial of service or disruption of the host environment. This vulnerability provides a delete-only capability and does not permit arbitrary file creation, modification, or code execution. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.1
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24979
GHSA-pqqc-8v73-9gg2
Sep 09, 2026
LF Edge eKuiper: SSRF in External Service
5.5
/ 10
Medium
Network
Low
High
None
Unchanged
High
Low
None
SummaryServer-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints. DetailsPrior to v2.4.0, eKuiper external service registrations and HTTP invocations did not validate destination IP addresses. An attacker with access to the eKuiper management API could register an external service pointing to an internal address (such as PoC
ImpactServer-Side Request Forgery (SSRF) allowing unauthorized access / probing of internal network services. Remediation & Patches
Workarounds (for versions < 2.4.0)If unable to upgrade immediately:
Notes for Users Upgrading to >= 2.4.0
Reported by Alexey Kosmachev, Bi.Zone Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
CVE-2025-24978
GHSA-g8rh-fjm6-h2h9
Sep 09, 2026
LF Edge eKuiper: Self-XSS in External Service Creation
3.7
/ 10
Low
Network
High
Low
Required
Unchanged
Low
Low
None
SummaryA Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. DetailsPrior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as PoC
ImpactSelf-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session. Remediation & Patches
Workarounds
Credits
Fixed in
2.4.0
References Updated Sep 09, 2026 · Source: OSV.dev
GO-2025-4158
GHSA-rj4j-2jph-gg43
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction in github.com/lf-edge/ekuiper Fixed in
2.3.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-54379
GO-2025-3827
GHSA-526j-mv3p-f4vv
PYSEC-2025-241
Jul 29, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper eKuiper API endpoints handling SQL queries with user-controlled table names. in github.com/lf-edge/ekuiper Fixed in
2.2.1
References Updated Jul 13, 2026 · Source: OSV.dev
GO-2025-3799
GHSA-fv2p-qj5p-wqq4
Jul 28, 2025
LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper LF Edge eKuiper vulnerable to File Path Traversal leading to file replacement in github.com/lf-edge/ekuiper Fixed in
2.2.0
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3800
GHSA-gj54-gwj9-x2c6
Jul 28, 2025
eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper eKuiper /config/uploads API arbitrary file writing may lead to RCE in github.com/lf-edge/ekuiper Fixed in
2.2.0
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52290
GO-2025-3682
GHSA-9cwv-pxcr-hfjc
May 15, 2025
LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality in github.com/lf-edge/ekuiper Fixed in
2.1.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-52812
GO-2025-3508
GHSA-6hrw-x7pr-4mp8
Mar 13, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper LF Edge eKuiper allows Stored XSS in Rules Functionality in github.com/lf-edge/ekuiper Fixed in
2.0.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v2.0.0-alpha.9
pre
Dependencies (57)
+ 49 more |