Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

rootio-golang-1.24: Unauthenticated RCE via Malformed Request

ROOT-OS-DEBIAN-13-CVE-2025-58188
Summary

An update was released for rootio-golang-1.24, which fixes a security issue that could allow an attacker to execute code without needing a password. This issue affects the Root platform, specifically the Debian 13 version. It's essential to update to a patched version to prevent unauthorized access to your system.

What to do
  • Update rootio-golang-1.24 to version 1.24.4-1.root.io.16.
Affected software
VendorProductAffected versionsFix available
– rootio-golang-1.24 <= 1.24.4-1.root.io.16 1.24.4-1.root.io.16
Original title
CVE-2025-58188 in rootio-golang-1.24 - Patched by Root
Original description
Root has patched CVE-2025-58188 in the rootio-golang-1.24 package for Root:Debian:13. Multiple fixed versions available.
Published: 6 Mar 2026 · Updated: 6 Mar 2026 · First seen: 6 Mar 2026