CVE-2025-27591Patch(facebook / below)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch facebook below systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • below

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
below

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-16: 1Patch / Workaround · 2026-02-16: 102-16
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Văn Lợi Nguyễn@NGLoiVN
    Patch

    @speedyfriend433 @zeroxjf writetosymlinked, it fixed , seem did you try with CVE-2025-27591, thanks for your work

    Post summary

    The user notes that CVE-2025-27591 has been fixed, with no additional exploitation or technical details provided.

    0001090
    21 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfacebookbelow-rust-

Explore more