Junglewise Threat Intelligence

CVE-2025-65530: CloudLinux ai-bolit eval injection in malware de-obfuscation routines

CVE-2025-65530 · Severity: high · CVSS 8.8 · Published 2025-12-12

Executive brief

CloudLinux ai-bolit is a malware scanner used in Imunify security products to protect web servers. A vulnerability in its malware detection engine allows an attacker to execute malicious code with root privileges by providing a specially crafted file for the system to scan. This could lead to a full server takeover, unauthorized file modification, or data theft.

Technical details

An eval injection vulnerability exists in the de-obfuscation logic of the AI-Bolit component within ai-bolit-hoster.php. Specifically, the functions 'deobfuscateDeltaOrd' and 'deobfuscateEvalHexFunc' call 'Helpers::executeWrapper()', which utilizes 'call_user_func_array()' on unfiltered strings extracted from scanned files. An attacker can exploit this by providing a crafted file or database entry that, when scanned, triggers the execution of arbitrary PHP functions. This allows for remote code execution and privilege escalation to root. The issue is resolved in version 32.7.4-1 by implementing a strict whitelist of safe functions for the de-obfuscator.

Affected products

  • CloudLinux ai-bolit before 32.7.4-1
  • CloudLinux Imunify360 before 32.7.4-1
  • CloudLinux ImunifyAV+ before 32.7.4-1
  • CloudLinux ImunifyAV before 32.7.4-1

Timeline

  • 2025-10-23: patched: Security patch released and automatically deployed to most servers.
  • 2025-11-17: advisory: Public security advisory published by Imunify.
  • 2025-12-12: disclosed: CVE published to NVD.

References