CVE-2025-53833Active Exploitation

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration. Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-25: 3Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-25: 302-25
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
Exploit
133.3%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CVE-2025-53833: Critical Vulnerability in Server Software Critical flaw with CVSS 10.0; exploits available; patches released. CVE: CVE-2025-53833 • APT: N/A • Status: EXPLOITED Unpatched servers are high-value targets for attack… https://strobes.co/vi/cve/CVE-2025-53833

    Post summary

    CVE-2025-53833 is a critical server vulnerability with a CVSS score of 10.0, actively exploited in the wild, and patches have already been released.

    000000
    3 followersView on X
  • mysocAi@MysocAi
    Exploit

    [CRITICAL] CVE-2025-53833: Critical Vulnerability with Public Exploits CVE-2025-53833 has a CVSS score of 10.0; exploits available; patch released. CVE: CVE-2025-53833 • APT: N/A • Status: ACTIVE High risk due to critical severity and … https://strobes.co/vi/cve/CVE-2025-53833

    Post summary

    CVE-2025-53833 is a critical vulnerability (CVSS 10.0) with publicly available exploits and a released patch, but no specific exploit code or PoC is provided.

    000001
    3 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [CRITICAL] CVE-2025-53833: Critical Vulnerability in Wwbn AVideo CVE-2025-53833 allows arbitrary command execution on Wwbn AVideo servers. CVE: CVE-2025-53833 • APT: Unknown • Status: ACTIVE Enables remote code execution, posing severe… https://strobes.co/vi/cve/CVE-2025-53833

    Post summary

    The post announces CVE-2025-53833, a critical remote code execution vulnerability in Wwbn AVideo, but provides no PoC, exploit, or patch details.

    000000
    3 followersView on X

Explore more