Arbitrary Code Injection The advisory has been revoked - it doesn't affect any version of package redis/redis  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.7% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-REDISREDIS-13332696
  • published6 Oct 2025
  • disclosed3 Oct 2025
  • creditzhutyra

Introduced: 3 Oct 2025

CVE-2025-46818  (opens in a new tab)
CWE-94  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Injection. An attacker can execute arbitrary code in the context of another user by crafting a malicious Lua script and leveraging authenticated access with scripting rights, combined with high-complexity steps and typically requiring another user's interaction for cross-context execution.

Note:

This is only exploitable if the attacker has authenticated access with scripting rights and can trigger a specific Lua code path, often requiring another user's action.