Known CVE
SawtoothSoftware Lighthouse Studio < 9.16.14 - Pre-Auth Remote Code Execution
A pre-authentication remote code execution vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14. The issue arises from the unsafe use of the `eval` function within the Perl CGI component `ciwweb.pl`, where attacker-supplied input inside `hid_Random_ACARAT` is directly passed to `eval`. This allows remote unauthenticated attackers to execute arbitrary Perl code on the server.
CVE-2025-34300
Critical2025CVSS 9.8CWE-1336CWE-20
cve2025 · lighthouse-studio · sawtoothsoftware · rce · ssti · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website