CVE-2025-27591

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:facebook:below:*:*:*:*:*:rust:*:*

History

No history.

Information

Published : 2025-03-11 19:15

Updated : 2025-07-03 14:40


NVD link : CVE-2025-27591

Mitre link : CVE-2025-27591

CVE.ORG link : CVE-2025-27591


JSON object : View

Products Affected

facebook

  • below
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource