CVE-2025-34300
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
| CWE | CWE-20 CWE-1336 |
| Vendor | sawtooth software |
| Product | lighthouse studio |
| Published | Jul 16, 2025 |
| Last Updated | May 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for sawtooth software lighthouse studio
Be the first to know when new unknown vulnerabilities affecting sawtooth software lighthouse studio are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Sawtooth Software / Lighthouse Studio
0 < 9.16.14
References
sawtoothsoftware.com: https://sawtoothsoftware.com/resources/software-downloads/lighthouse-studio/version-history slcyber.io: https://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/ vulncheck.com: https://www.vulncheck.com/advisories/sawtooth-software-lighthouse-studio-preauthentication-rce
Credits
Adam Kues - Assetnote