---
id: CVE-2025-13428
title: A vulnerability exists in the SecOps SOAR server
summary: >-
  A vulnerability exists in the SecOps SOAR server. The custom integrations
  feature allowed an authenticated user with an "IDE role" to achieve Remote
  Code Execution (RCE) in the server. The flaw stemmed from weak validation of
  uploaded Py…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: google
product: security_operations_soar
affected:
  - security_operations_soar < 6.3.64
patched:
  - security_operations_soar 6.3.64
published: '2025-12-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:10:00.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13428'
references:
  - url: 'https://cloud.google.com/support/bulletins#gcp-2025-075'
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
epss: 0.00328
epssPercentile: 0.23449
ingestedAt: '2026-09-30T17:13:20.753Z'
---

## Overview

A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validation of uploaded Python package code. An attacker could upload a package containing a malicious setup.py file, which would execute on the server during the installation process, leading to potential server compromise.

No customer action is required. 


All customers have been automatically upgraded to the fixed version: 6.3.64 or higher.

## Affected

- `security_operations_soar < 6.3.64`

## Remediation

Upgrade past the affected range:

- `security_operations_soar 6.3.64`
