Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

CVE-2025-27137

MediumCVSS 4.4 / 10
Published Feb 24, 2025·Last modified Apr 10, 2026
Affected Components(0)

No affected components available

Description

Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the SYSTEM_CONFIGURATION permission to customize notification templates. Templates are evaluated using the Pebble template engine. Pebble supports an include tag, which allows template authors to include the content of arbitrary files upon evaluation. Prior to version 4.12.6, users of Dependency-Track with the SYSTEM_CONFIGURATION permission can abuse the include tag by crafting notification templates that include sensitive local files, such as /etc/passwd or /proc/1/environ. By configuring such a template for a notification rule (aka "Alert"), and having it send notifications to a destination controlled by the actor, sensitive information may be leaked. The issue has been fixed in Dependency-Track 4.12.6. In fixed versions, the include tag can no longer be used. Usage of the tag will cause template evaluation to fail. As a workaround, avoid assigning the SYSTEM_CONFIGURATION permission to untrusted users. The SYSTEM_CONFIGURATION permission per default is only granted to members of the Administrators team. Assigning this permission to non-administrative users or teams is a security risk in itself, and highly discouraged.

Risk Scores
Base Score
4.4

The vulnerability requires local access to the device to be exploited. It is easy for an attacker to exploit this vulnerability. An attacker needs high-level or administrative privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information.

Threat Intelligence
4.1

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.18%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard