A critical vulnerability, CVE-2025-46295, has been identified in Apache Commons Text, allowing for potential remote code execution when untrusted input is passed into the text-substitution API. The flaw, which affects versions prior to 1.10.0, stems from the abuse of interpolation features that could trigger command execution or access to external resources. Security researchers warn that exploitation of this vulnerability could result in total server takeover if left unpatched, and the issue has been fully addressed in FileMaker Server 22.0.4.
Organizations using Apache Commons Text in their applications are urged to update to the latest version to mitigate the risk. The vulnerability has been rated with a CVSS score of 9.8, underscoring its severity and the urgency for remediation. No specific products have been listed as affected yet, but the risk applies broadly to any software leveraging vulnerable versions of the library.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-46295 was published as a critical Apache Commons Text vulnerability with a CVSS 3.1 score of 9.8, indicating remote exploitability without user interaction or privileges. Public advisories warned that vulnerable applications could face command injection and possible remote code execution.
Claris addressed the vulnerability in FileMaker Server version 22.0.4 by updating the bundled Apache Commons Text library to a fixed release. The issue was described as fully addressed in that version.
Claris FileMaker credited an anonymous researcher with responsibly reporting a critical command injection/remote code execution issue in Apache Commons Text affecting versions prior to 1.10.0. The flaw stems from unsafe interpolation features that can be abused when untrusted input is processed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.