
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11195 is a project name validation vulnerability in Rapid7 AppSpider Pro affecting all versions below 7.5.021. An attacker with local access can directly modify the application's configuration file to assign a project name that already exists, bypassing the application's uniqueness enforcement. The vulnerability was disclosed on September 30, 2025, and remediated in version 7.5.021 released September 11, 2025. It carries a CVSS v3.1 base score of 3.3 (Low), assigned by Rapid7 (Rapid7 Advisory, Feedly).
The root cause is classified under CWE-20 (Improper Input Validation) and CWE-345 (Insufficient Verification of Data Authenticity). The application enforces project name uniqueness only within its UI; when a user edits the configuration file directly outside the application, no server-side or file-level validation is performed to detect duplicate project names. Exploitation requires local access and low privileges — an attacker must be able to read and write the AppSpider Pro configuration file on the host system. No public proof-of-concept or technical write-up beyond the vendor advisory is currently available (Feedly, Rapid7 Advisory).
Successful exploitation is limited to integrity impact — an attacker can manipulate project configurations by assigning duplicate project names, potentially causing confusion, data conflicts, or disruption in project management workflows within AppSpider Pro. There is no confidentiality or availability impact, and the vulnerability does not enable remote code execution, privilege escalation, or lateral movement. The scope is confined to the local AppSpider Pro installation (Feedly).
There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with this vulnerability. The EPSS score is approximately 0.009% (0.000090), indicating an extremely low probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
Rapid7 has remediated this vulnerability in AppSpider Pro version 7.5.021, released September 11, 2025. Users should upgrade to version 7.5.021 or later as the primary remediation step. As interim workarounds, organizations should restrict local filesystem access to AppSpider Pro configuration files using strict OS-level permissions, limit local user accounts with access to the application directory, and implement file integrity monitoring on configuration files to detect unauthorized changes (Rapid7 Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."