CVE-2025-1385 - CVE House
Back to Database
Status published High CVE-2025-1385

Fail input validation in clickhouse-library-bridge API could lead to RCE under specific configuration

Vulnerability Description

When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to specific directories, a misconfigured server can be exploited by an attacker with privilege to access to both table engines to execute arbitrary code on the ClickHouse server. You can check if your ClickHouse server is vulnerable to this vulnerability by inspecting the configuration file and confirming if the following setting is enabled: <library_bridge> <port>9019</port> </library_bridge>

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1385

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Arseniy Dugin

Affected Vendor

Affected Software

ClickHouse OSS
Vulnerable Versions:
24.3, 24.8, 24.11, 24.12, 25.1

Timeline

Official Publish: March 20th, 2025
Last Modified: March 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)