---
id: CVE-2025-8868
title: >-
  In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86
  platform, an authenticated attacker can gain access to Chef Automate
  restricted functionality in the compliance service via 


  improperly neutralized inputs used in a…
summary: >-
  In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86
  platform, an authenticated attacker can gain access to Chef Automate
  restricted functionality in the compliance service via 


  improperly neutralized inputs used in a…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
  - CWE-200
  - CWE-89
vendor: chef
product: automate
affected:
  - automate < 4.13.295
  - 'automate >= 20180319150121, <= 20220329091442'
patched:
  - automate 4.13.295
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8868'
references:
  - url: 'https://docs.chef.io/release_notes_automate/#4.13.295'
    label: security@progress.com
tags:
  - nvd
  - exploit-available
epss: 0.24317
epssPercentile: 0.97815
exploits:
  nuclei:
    - CVE-2025-8868
  checkedAt: '2026-10-09T09:31:35.727Z'
exploitAvailable: true
ingestedAt: '2026-10-09T09:31:00.982Z'
---

## Overview

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via 

improperly neutralized inputs used in an SQL command using a well-known token.

## Affected

- `automate < 4.13.295`
- `automate >= 20180319150121, <= 20220329091442`

## Remediation

Upgrade past the affected range:

- `automate 4.13.295`
