Vulnerability record · CVE-2025-49002 · published 3 June 2025
CVE-2025-49002: DataEase patch bypass allows case-insensitive command execution
Dataease · Dataease
DataEase versions before 2.10.10 contain an incomplete fix for CVE-2025-32966: the blocklist that prohibits INIT and RUNSCRIPT can be bypassed because the check is case-insensitive, letting those commands through. This matters because the underlying flaw is a remote code execution path in an open source BI tool, and no workarounds exist other than upgrading.
Description
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit references and very high EPSS, though not yet in KEV and requiring some attack complexity.
What it is
DataEase versions before 2.10.10 contain an incomplete fix for CVE-2025-32966: the blocklist that prohibits INIT and RUNSCRIPT can be bypassed because the check is case-insensitive, letting those commands through. This matters because the underlying flaw is a remote code execution path in an open source BI tool, and no workarounds exist other than upgrading.
Impact
An attacker can execute arbitrary commands on the DataEase server, leading to full compromise of the host and any data it can reach.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The specific endpoint is not named in the record, so defenders should treat any interface that reaches the vulnerable command-handling logic as exposed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.50266 (98.8th percentile) and both advisory references are tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Upgrade DataEase to version 2.10.10 or later, which contains the fix.
- If immediate upgrade is impossible, restrict network access to the DataEase service to trusted hosts only, since no official workaround exists.
- Audit for any prior exploitation attempts before patching, as the flaw predates the fix.
- Monitor DataEase release notes and advisories for any follow-up bypasses of the same command blocklist.
Detection
- Search DataEase logs for INIT and RUNSCRIPT command strings in any casing, including mixed case variants.
- Alert on unexpected child processes spawned by the DataEase service account.
- Monitor outbound network connections from the DataEase host to unfamiliar destinations.
- Review access logs for unauthenticated requests to endpoints that handle command or script input.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/dataease/dataease/security/advisories/GHSA-999m-jv2p-5h34 | ExploitThird Party Advisory |
| https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 | ExploitThird Party Advisory |
| https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-4j78-cvc7 | ExploitThird Party Advisory |
Track CVE-2025-49002 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-49002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.