CVE-2025-11195
AppSpider vulnerability analysis and mitigation

Overview

CVE-2025-11195 is a project name validation vulnerability in Rapid7 AppSpider Pro affecting all versions below 7.5.021. An attacker with local access can directly modify the application's configuration file to assign a project name that already exists, bypassing the application's uniqueness enforcement. The vulnerability was disclosed on September 30, 2025, and remediated in version 7.5.021 released September 11, 2025. It carries a CVSS v3.1 base score of 3.3 (Low), assigned by Rapid7 (Rapid7 Advisory, Feedly).

Technical details

The root cause is classified under CWE-20 (Improper Input Validation) and CWE-345 (Insufficient Verification of Data Authenticity). The application enforces project name uniqueness only within its UI; when a user edits the configuration file directly outside the application, no server-side or file-level validation is performed to detect duplicate project names. Exploitation requires local access and low privileges — an attacker must be able to read and write the AppSpider Pro configuration file on the host system. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (Feedly, Rapid7 Advisory).

Impact

Successful exploitation is limited to integrity impact — an attacker can manipulate project configurations by assigning duplicate project names, potentially causing confusion, data conflicts, or disruption in project management workflows within AppSpider Pro. There is no confidentiality or availability impact, and the vulnerability does not enable remote code execution, privilege escalation, or lateral movement. The scope is confined to the local AppSpider Pro installation (Feedly).

Exploitability

There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with this vulnerability. The EPSS score is approximately 0.009% (0.000090), indicating an extremely low probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Gain local access: Obtain low-privileged local access to a system running Rapid7 AppSpider Pro below version 7.5.021.
  2. Locate the configuration file: Navigate to the AppSpider Pro installation directory and identify the project configuration file (e.g., an XML or JSON file storing project metadata including project names).
  3. Identify existing project names: Review the configuration file or application UI to enumerate existing project names.
  4. Modify the configuration file: Directly edit the configuration file outside the application, changing a project's name field to match an already-existing project name.
  5. Trigger the conflict: Reload or interact with AppSpider Pro so it processes the modified configuration, resulting in duplicate project name entries and potential integrity issues in project management (Feedly, Rapid7 Advisory).

Indicators of compromise

  • File System: Unexpected or unauthorized modifications to AppSpider Pro project configuration files (e.g., timestamps changed outside normal application usage hours); presence of duplicate project name entries within configuration files.
  • Logs: Application logs showing errors or warnings related to duplicate project names or configuration conflicts upon loading; audit logs recording file modifications to AppSpider Pro configuration directories by non-administrative accounts.

Mitigation and workarounds

Rapid7 has remediated this vulnerability in AppSpider Pro version 7.5.021, released September 11, 2025. Users should upgrade to version 7.5.021 or later as the primary remediation step. As interim workarounds, organizations should restrict local filesystem access to AppSpider Pro configuration files using strict OS-level permissions, limit local user accounts with access to the application directory, and implement file integrity monitoring on configuration files to detect unauthorized changes (Rapid7 Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Related AppSpider vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2017-5236HIGH7.8
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 03, 2017
CVE-2017-5240HIGH7.5
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 03, 2017
CVE-2025-4951MEDIUM4.6
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 20, 2025
CVE-2025-11195LOW3.3
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesSep 30, 2025
CVE-2025-36857LOW3.3
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesSep 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management