Ad

CVE-2025-27090

MEDIUM CVSS 4.0: 6.9 EPSS 0.81%
Updated Feb 27, 2025
Bishopfox
Parameter Value
CVSS 6.9 (MEDIUM)
Affected Versions 1.5.26 — 1.5.43
Fixed In 1.5.43
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Bishopfox
Public PoC No

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party.

This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Bishopfox Sliver
cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:*
1.5.26 1.5.43