CVE-2025-69517Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creation of a new agent via the POST /api/v3/newagent/ endpoint. The agent_id parameter accepts up to 255 characters and is improperly sanitized using DOMPurify.sanitize() with the html: true option enabled, which fails to adequately filter HTML input. The injected HTML is rendered in the Tactical RMM management panel when an administrator attempts to remove or shut down the affected agent, potentially leading to client-side attacks such as UI manipulation or phishing. NOTE: the Supplier's position is that this has incorrect information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-01-28: 1Mentions · 2026-01-29: 2Mentions · 2026-01-30: 2Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 101-2801-2901-30
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-01-292
Disclosure2
2026-01-302
Disclosure1General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-69517 An issue in Amidaware Inc Tactical RMM v1.3.1 and before allows a remote attacker to execute arbitrary code via the /api/tacticalrmm/apiv3/views.py component https://www.cve.org/CVERecord?id=CVE-2025-69517

    Post summary

    The post discloses a remote code execution vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier, via the "/api/tacticalrmm/apiv3/views.py" component, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    02020293
    56.5K followersView on X
  • ‘BugBounty Writeups’@bbwriteups
    Disclosure

    "CVE-2025-69517 — Critical Remote Code Execution, TacticalRMM" by Rony Das #BugBounty #Cybersecurity #Hacking #InfoSec https://ronydasx.medium.com/cve-2025-69517-critical-remote-code-execution-tacticalrmm-07146c1b6f7c

    Post summary

    The text announces CVE-2025-69517 as a critical RCE vulnerability affecting TacticalRMM, but offers no further details on PoC, exploit, or patch.

    11010203
    479 followersView on X
  • Sniss7k@SNISS8
    General

    @bbwriteups Is the CVE-2025-69516! Not the CVE-2025-69517

    Post summary

    The tweet simply corrects the CVE identifier, with no additional technical or exploit details.

    00010104
    50 followersView on X
  • Sniss7k@SNISS8
    Disclosure

    My 2 new CVES!! https://www.cve.org/CVERecord?id=CVE-2025-69516 https://www.cve.org/CVERecord?id=CVE-2025-69517 The first one allows RCE using SSTI and the second one is a html injection storage! Both on TacticalRMM Thanks for my teammates: m0unt ( Ntgabriel) and 0xL1zard

    Post summary

    The user is announcing two new CVEs against TacticalRMM, noting an RCE through SSTI for CVE-2025-69516 and an HTML injection issue for CVE-2025-69517.

    00000137
    50 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-69517 - Critical An issue in Amidaware Inc Tactical RMM v1.3.1 and before allows a remote attacker to execute arbitrary code via the /api/tacticalrmm/apiv3/views.py component https://www.thehackerwire.com/vulnerability/CVE-2025-69517/ https://t.co/ZJ06YIvZ7E

    Post summary

    A critical remote code execution vulnerability (CVE-2025-69517) is disclosed in Amidaware Tactical RMM v1.3.1 via a specific API component, with no evidence of exploitation or remediation mentioned.

    00000111
    113 followersView on X

Explore more