Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extensions to bypass the upload filter.
id: CVE-2025-1025
info:
name: Cockpit < 2.4.1 - Arbitrary File Upload
author: iamnoooob,rootxha
...