In EMQX before 5.8.6, administrators can install...
Low severity
Unreviewed
Published
Aug 10, 2025
to the GitHub Advisory Database
•
Updated Aug 10, 2025
Description
Published by the National Vulnerability Database
Aug 10, 2025
Published to the GitHub Advisory Database
Aug 10, 2025
Last updated
Aug 10, 2025
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
References