In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
No PoCs from references.
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/fatkz/CVE-2025-27590
- https://github.com/nomi-sec/PoC-in-GitHub