Hoverfly versions 1.11.3 and below are vulnerable to remote code execution (RCE) via command injection in the middleware API endpoint (/api/v2/hoverfly/middleware). Insufficient validation of the 'binary' and 'script' parameters allows an unauthenticated attacker to execute arbitrary commands on the host system.
id: CVE-2025-54123
info:
name: Hoverfly <= 1.11.3 - Remote Code Execution
author: nukunga[seong
...