---
id: CVE-2025-6724
title: >-
  In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86
  platform, an authenticated attacker can gain access to Chef Automate
  restricted functionality in multiple services via improperly neutralized
  inputs used in an SQL c…
summary: >-
  In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86
  platform, an authenticated attacker can gain access to Chef Automate
  restricted functionality in multiple services via improperly neutralized
  inputs used in an SQL c…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: chef
product: automate
affected:
  - automate < 4.13.295
  - 'automate >= 20180319150121, <= 20220329091442'
patched:
  - automate 4.13.295
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6724'
references:
  - url: 'https://docs.chef.io/release_notes_automate/#4.13.295'
    label: security@progress.com
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.28457
ingestedAt: '2026-10-09T09:31:00.981Z'
---

## Overview

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.

## Affected

- `automate < 4.13.295`
- `automate >= 20180319150121, <= 20220329091442`

## Remediation

Upgrade past the affected range:

- `automate 4.13.295`
