RediShell RCE Vulnerability

What is the Vulnerability?

A Use-After-Free (UAF) bug in Redis’s Lua scripting subsystem (tracked as CVE-2025-49844, “RediShell”) allows an authenticated attacker who can run Lua scripts to escape the Lua sandbox and achieve arbitrary native code execution on the Redis host.

This is a critical (CVSS 10.0), high-impact vulnerability because Lua scripting is enabled by default and many deployments lack proper authentication or are internet-exposed, leading to theft of credentials, deployment of malware/miners, lateral movement, exfiltration, and loss of availability.

What is the recommended Mitigation?

  • Patches were released on October 3, 2025. Redis Cloud was automatically patched, but self-managed instances must be upgraded immediately.

  • Upgrade all self-managed Redis instances to one of the fixed versions listed in the Redis advisory. Redis Cloud customers were auto-patched.

  • If you cannot patch immediately, apply temporary mitigations:

    Disable Lua scripting where it’s not required for application functionality. If Lua is required, restrict which identities can run scripts and monitor their usage.

What FortiGuard Coverage is available?

Read More 


Posted

in

by

Tags: