Security Digest: December 2, 2025 - 4 Critical Vulnerabilities

Today's security alert highlights four critical vulnerabilities affecting various systems. Immediate patching and configuration changes are essential.

· 4 min read

Security Digest: December 2, 2025 - Critical Vulnerabilities Discovered

Executive Summary

Today's security alert highlights four critical vulnerabilities affecting various systems, including npm packages and Grav CMS. Immediate patching and configuration changes are essential to safeguard your environments from potential remote code execution and privilege escalation threats.

Critical Vulnerabilities

  • CVE-2025-66401: Critical Command Injection in MCPScanner
    • Impact: Allows attackers to execute arbitrary commands, potentially leading to full server control.
    • Affected Systems: npm package mcp-watch
    • Immediate Action: Disable the use of execSync in cloneRepo method or replace with a safer alternative. Validate and sanitize user inputs.
    • Mitigation: Apply input validation and escape shell metacharacters in URLs.
  • CVE-2025-66299: SSTI in Grav CMS
    • Impact: Enables remote code execution by authenticated users.
    • Affected Systems: Grav CMS via composer package getgrav/grav
    • Immediate Action: Restrict editor permissions and review configuration for Twig template filters.
    • Mitigation: Apply patches provided by Grav CMS and ensure safe configuration of Twig filters.
  • CVE-2025-66296: Privilege Escalation in Grav CMS
    • Impact: Users can escalate privileges to administrator by creating accounts with existing usernames.
    • Affected Systems: Grav CMS via composer package getgrav/grav
    • Immediate Action: Implement username uniqueness checks and update user creation logic.
    • Mitigation: Check for patches from Grav CMS and enforce stricter user account controls.
  • CVE-2025-66300: File Read Vulnerability via Frontmatter in Grav CMS
    • Impact: Allows low privilege users to read sensitive server files, potentially leading to account compromise.
    • Affected Systems: Grav CMS via composer package getgrav/grav
    • Immediate Action: Limit page editing privileges and review form configuration.
    • Mitigation: Apply updates from Grav CMS and audit configurations for Frontmatter usage.

Previously Alerted

What to Do Now

  1. Review and apply available patches for all affected systems immediately.
  2. Conduct a security audit of privileges and configurations, especially for Grav CMS installations.
  3. Monitor server logs for unusual activity, particularly around user account changes and command executions.

Related Resources

  • Consider reading internal blog posts on secure coding practices and access control management for further guidance.
  • Refer to official advisories from npm and Grav CMS for detailed patch information.

Keep reading