Executive brief
LimeSurvey, a popular open-source online survey application, contains a critical security flaw that allows unauthorized individuals to take control of the server. By sending a specially crafted request, an attacker can execute their own commands, potentially leading to the theft of survey data, modification of results, or a complete shutdown of the service. Organizations using LimeSurvey should update to the latest version immediately to protect their data and operations.
Technical details
A critical deserialization vulnerability (CWE-502) exists in LimeSurvey versions prior to 6.15.0+250623. The application improperly handles user-controlled input during the deserialization process, allowing an attacker to provide a specially crafted serialized object. This can be exploited remotely without authentication to trigger arbitrary code execution within the application context. The vulnerability is reachable over the network and poses a high risk to confidentiality, integrity, and availability. Users are advised to upgrade to version 6.15.0+250623 or later to mitigate this risk.
Affected products
- LimeSurvey LimeSurvey < 6.15.0+250623
Timeline
- 2026-03-10: advisory: Initial disclosure of CVE-2025-56422
- 2026-03-10: patched: Fix released in version 6.15.0+250623