Junglewise Threat Intelligence

CVE-2025-53867: Island Lake WebBatch remote code execution via crafted URL

CVE-2025-53867 · Severity: critical · CVSS 9.8 · Published 2025-07-17

Executive brief

Island Lake WebBatch, a tool used to create web-based applications and scripts, contains a critical security vulnerability. An attacker can exploit this by sending a specially crafted web link to the server, allowing them to execute unauthorized commands on the underlying system. This could lead to a complete takeover of the server, theft of sensitive data, or disruption of business operations.

Technical details

Island Lake WebBatch versions prior to 2025C contain a code injection vulnerability (CWE-94) that facilitates remote code execution. The flaw exists in how the application processes incoming URL parameters, failing to properly sanitize input before it is used in a context that allows command execution. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request containing system commands. Successful exploitation results in the execution of arbitrary commands with the privileges of the WebBatch process. The issue is resolved in version 2025C.

Affected products

  • Island Lake WebBatch before 2025C

Timeline

  • 2025-07-15: patched: WebBatch 2025C released to address the vulnerability.
  • 2025-07-17: advisory: CVE-2025-53867 published.

References