CVEFind.com@CveFindComDisclosure
A critical RCE vulnerability (CVE‑2025‑11158) in Hitachi Vantara Pentaho Data Integration & Analytics before version 10.2.0.6 is disclosed, highlighting the need for an update.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new RCE vulnerability (CVE‑2025‑11158) affecting Hitachi Vantara Pentaho versions prior to 10.2.0.6 is announced, with no proof‑of‑concept, exploit, active‑exploitation, patch, or false‑positive information provided.
The Hacker Wire@TheHackerWireDisclosure
CVE-2025-11158 is a disclosed vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics that allows unrestricted Groovy scripts in user‑created PRPT reports, but no PoC, exploit code, active exploitation, or patch information is provided.
Moshe Siman Tov Bustan@MosheTovDisclosure
A critical RCE (CVE‑2025‑11158) in Pentaho has been disclosed with a CVSS score of 9.1, where a single report upload can take over the system. No patch or exploit code is included, but a blog post link is provided.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2025‑11158, describing a Groovy script injection in Pentaho Data Integration that gives authenticated users instant RCE on versions below 10.2.0.6, and links to detailed vulnerability information.