References https://nvd.nist.gov/vuln/detail/CVE-2025-54123 https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-r4h8-hfp2-ggmf https://github.com/advisories/GHSA-r4h8-hfp2-ggmf https://www.sentinelone.com/vulnerability-database/cve-2025-54123/ https://github.com/davidzzo23/CVE-2025-54123 https://github.com/f4dee-backup/CVE-2025-54123 https://pentest-tools.com/vulnerabilities-exploits/hoverfly-remote-code-execution_29145 https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSPECTOLABSHOVERFLYCORE-12671221 https://github.com/kasem545/CVE-2025-54123-Poc https://www.ameeba.com/blog/cve-2025-54123-remote-code-execution-vulnerability-in-hoverfly-api-simulation-tool/
Related VulnerabilitiesHoverfly /api/v2/ws/logs 信息泄露漏洞Hoverfly /api/v2/hoverfly/middleware 命令执行漏洞(CVE-2025-54123)(CVE-2025-54123) Hoverfly 中间件API命令注入漏洞PoCCVE-2024-45388: Hoverfly < 1.10.3 - Arbitrary File ReadPoCCVE-2025-54123: Hoverfly <= 1.11.3 - Remote Code ExecutionHoverfly 任意文件读取漏洞(CVE-2024-45388)Hoverfly /api/v2/simulation 任意文件读取漏洞