CVE-2025-54389 Details
Description
AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tamper with the log output. A local user might exploit this to bypass the AIDE detection of malicious files. Additionally the output of extended attribute key names and symbolic links targets are also not properly neutralized. This issue has been patched in version 0.19.2. A workaround involves configuring AIDE to write the report output to a regular file, redirecting stdout to a regular file, or redirecting the log output written to stderr to a regular file.
A vulnerability has been identified in AIDE (Advanced Intrusion Detection Environment) versions prior to 0.19.2, allowing local users to bypass detection of malicious files. This is achieved by crafting filenames that include terminal escape sequences, which can obscure the addition or removal of files in AIDE's reports. The vulnerability also affects the output of extended attribute key names and symbolic link targets, which are not properly sanitized before being logged or reported.
Users are advised to upgrade to AIDE version 0.19.2, where this vulnerability has been patched. If an upgrade is not possible, AIDE can be configured to write report outputs to a regular file, redirecting standard output or the log output from standard error to a file. Be sure to open these files with a program that correctly interprets terminal escape sequences.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aide/aide/security/advisories/GHSA-522j-vvx9-gg28 | CISA-ADP | ExploitMitigationVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2025/08/msg00011.html | CVE | |
| http://www.openwall.com/lists/oss-security/2025/08/14/7 | CVE | |
| https://github.com/aide/aide/commit/64c8f32b0349c33fb8382784af468338078851f9 | [email protected] | Patch |
| https://github.com/aide/aide/releases/tag/v0.19.2 | [email protected] | Release Notes |
| https://github.com/aide/aide/security/advisories/GHSA-522j-vvx9-gg28 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-117 | Improper Output Neutralization for Logs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| advanced intrusion detection environment project advanced intrusion detection environment | < 0.19.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 19, 2025 | Initial Analysis | [email protected] |
| Aug 14, 2025 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | New CVE Received | [email protected] |