CVE-2025-36857
AppSpider vulnerability analysis and mitigation

Overview

CVE-2025-36857 is a broken access control vulnerability (CWE-276: Incorrect Default Permissions) in Rapid7 AppSpider Pro's configuration file loading mechanism. It affects all versions of AppSpider Pro below 7.5.021, allowing standard (low-privileged) users to place custom configuration files into directories belonging to other users or projects. Because configuration files are loaded in alphabetical order, a malicious file can override or alter the settings of legitimate configuration files. The vulnerability was disclosed on September 25, 2025, and carries a CVSS v3.1 base score of 3.3 (Low) (Rapid7 Release Notes, ENISA EUVD).

Technical details

The root cause is improper directory access management (CWE-276: Incorrect Default Permissions), where the application fails to enforce adequate access controls on configuration file directories. Standard users are permitted to write custom configuration files into directories that should be restricted to other users or projects. Because AppSpider Pro loads configuration files in alphabetical order, an attacker can craft a filename that sorts before the legitimate configuration file, causing their malicious settings to take precedence and override the original configuration. Exploitation requires local access and low-level privileges on the affected system; no network-based attack vector exists (Rapid7 Release Notes, ENISA EUVD).

Impact

Successful exploitation allows a low-privileged local attacker to manipulate application configuration settings for other users or projects within AppSpider Pro, compromising the integrity of scan configurations. This could result in unauthorized changes to scan behavior, potentially causing scans to target unintended systems, suppress findings, or alter security testing parameters. There is no direct confidentiality or availability impact (CVSS scores both as None), and the scope is limited to the local system without evidence of lateral movement potential (ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least standard user privileges, significantly limiting the attacker pool (ENISA EUVD).

Exploitation steps

  1. Gain local access: Obtain a standard (low-privileged) user account on a system running Rapid7 AppSpider Pro below version 7.5.021.
  2. Identify target directories: Enumerate configuration file directories belonging to other users or projects on the system, leveraging the improper directory permissions to gain write access.
  3. Craft a malicious configuration file: Create a custom configuration file with a filename that alphabetically precedes the legitimate configuration file (e.g., prefixing the filename with 'aaa_' or '0_') to ensure it is loaded first.
  4. Place the file: Write the crafted configuration file into the target user's or project's configuration directory, exploiting the lack of proper access controls.
  5. Trigger configuration load: Wait for or trigger AppSpider Pro to load configurations (e.g., by initiating a scan), causing the malicious file to be loaded first and override the legitimate settings, altering scan behavior for the targeted user or project (ENISA EUVD, Rapid7 Release Notes).

Indicators of compromise

  • File System: Unexpected configuration files appearing in AppSpider Pro user or project configuration directories, particularly files with names alphabetically preceding legitimate configuration files (e.g., filenames starting with numbers or 'aaa').
  • File System: Configuration files with unexpected ownership or creation timestamps inconsistent with the directory owner's activity.
  • Logs: AppSpider Pro logs showing configuration files being loaded from unexpected paths or by unexpected user accounts.
  • Logs: Scan configuration validation errors or warnings related to duplicate names or directory conflicts (as noted in the 7.5.021 release notes, which added enhanced validation).

Mitigation and workarounds

Rapid7 remediated this vulnerability in AppSpider Pro version 7.5.021, released September 11, 2025, which includes improved scan data directory permission policies and validation, as well as enhanced scan configuration validation to prevent duplicate names and directory conflict handling. Organizations should upgrade to version 7.5.021 or later immediately. As interim workarounds, administrators should implement strict OS-level access controls on AppSpider Pro configuration directories, limit standard user write permissions to only their own directories, and regularly audit file permissions and configuration directories for unauthorized files (Rapid7 Release Notes).

Additional resources


SourceThis report was generated using AI

Related AppSpider vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2017-5236HIGH7.8
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 03, 2017
CVE-2017-5240HIGH7.5
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 03, 2017
CVE-2025-4951MEDIUM4.6
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesMay 20, 2025
CVE-2025-11195LOW3.3
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesSep 30, 2025
CVE-2025-36857LOW3.3
  • AppSpider logoAppSpider
  • cpe:2.3:a:rapid7:appspider_pro
NoYesSep 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management