CVE-2025-61668 is a low severity vulnerability with a CVSS score of 0.0. No known exploits currently, and patches are available.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.
The problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:
Make sure your setup automatically restarts processes that quit with an error. This won't prevent a crash, but it minimises downtime.
The problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team ([email protected]).
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.