CVE-2025-34095 - CVE House
Back to Database
Status published Critical CVE-2025-34095

Mako Server v2.5 and v2.6 OS Command Injection via examples/save.lsp

Vulnerability Description

An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os.execute() code, which is then persisted on disk and triggered via a subsequent GET request to examples/manage.lsp. This allows remote command execution on the underlying operating system, impacting both Windows and Unix-based deployments.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34095

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • John Page (hyp3rlinx) of Beyond Security SecuriTeam Secure Disclosure

Affected Vendor

Real Time Logic

View all reports →

Affected Software

Mako Server
Vulnerable Versions:
2.5

Timeline

Official Publish: July 10th, 2025
Last Modified: May 14th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)