{"id":"CVE-2025-1131","summary":"Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation","details":"A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions.\n\n\nNon-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.","aliases":["GHSA-v9q8-9j8m-5xwp"],"modified":"2026-08-12T03:51:21.157871613Z","published":"2025-09-23T04:31:02.784Z","database_specific":{"cna_assigner":"Gridware","cwe_ids":["CWE-427"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1131.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1131.json"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-v9q8-9j8m-5xwp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1131"},{"type":"PACKAGE","url":"https://github.com/asterisk/asterisk"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"544aceb34f061af5371994e9e0701e0231d4409f"},{"introduced":"c6c7103efa6605a6db7ca28b4b17cd2d1c15a05c"},{"fixed":"21d22b328a0ee310df50868c36d6d466d111f133"},{"introduced":"12da95e53ff42287ad69d6d5922e06c3d62010ac"},{"fixed":"ff38e11ded47cb69adc1ec0c14e2a45aa7bf50da"},{"introduced":"8e4a09f71162ebc1e4bb2159dfc638aa2328047c"},{"fixed":"9130399bb961771b0acd2a137c7dd64715ece417"},{"introduced":"184c95dc01576b538c938b3b0fe2c8bf62102d33"},{"last_affected":"5b15600bd766b21b12a5d73e3050e3ec4f2e8db9"}],"database_specific":{"cpe":["cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert5:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert6:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"18.26.3"},{"introduced":"20.0.0"},{"fixed":"20.15.1"},{"introduced":"21.0.0"},{"fixed":"21.10.1"},{"introduced":"22.0.0"},{"fixed":"22.5.1"},{"introduced":"18.9-cert1"},{"last_affected":"18.9-cert1"},{"introduced":"18.9-cert1\\-rc1"},{"last_affected":"18.9-cert1\\-rc1"},{"introduced":"18.9-cert10"},{"last_affected":"18.9-cert10"},{"introduced":"18.9-cert11"},{"last_affected":"18.9-cert11"},{"introduced":"18.9-cert12"},{"last_affected":"18.9-cert12"},{"introduced":"18.9-cert13"},{"last_affected":"18.9-cert13"},{"introduced":"18.9-cert14"},{"last_affected":"18.9-cert14"},{"introduced":"18.9-cert15"},{"last_affected":"18.9-cert15"},{"introduced":"18.9-cert2"},{"last_affected":"18.9-cert2"},{"introduced":"18.9-cert3"},{"last_affected":"18.9-cert3"},{"introduced":"18.9-cert4"},{"last_affected":"18.9-cert4"},{"introduced":"18.9-cert5"},{"last_affected":"18.9-cert5"},{"introduced":"18.9-cert6"},{"last_affected":"18.9-cert6"},{"introduced":"18.9-cert7"},{"last_affected":"18.9-cert7"},{"introduced":"18.9-cert8"},{"last_affected":"18.9-cert8"},{"introduced":"18.9-cert8\\-rc1"},{"last_affected":"18.9-cert8\\-rc1"},{"introduced":"18.9-cert8\\-rc2"},{"last_affected":"18.9-cert8\\-rc2"},{"introduced":"18.9-cert9"},{"last_affected":"18.9-cert9"},{"introduced":"20.7-cert1"},{"last_affected":"20.7-cert1"},{"introduced":"20.7-cert1\\-rc1"},{"last_affected":"20.7-cert1\\-rc1"},{"introduced":"20.7-cert1\\-rc2"},{"last_affected":"20.7-cert1\\-rc2"},{"introduced":"20.7-cert2"},{"last_affected":"20.7-cert2"},{"introduced":"20.7-cert3"},{"last_affected":"20.7-cert3"},{"introduced":"20.7-cert4"},{"last_affected":"20.7-cert4"},{"introduced":"20.7-cert5"},{"last_affected":"20.7-cert5"},{"introduced":"20.7-cert6"},{"last_affected":"20.7-cert6"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["18.9-cert1","18.9-cert10","18.9-cert11","18.9-cert12","18.9-cert13","18.9-cert14","18.9-cert15","18.9-cert1\\-rc1","18.9-cert2","18.9-cert3","18.9-cert4","18.9-cert5","18.9-cert6","18.9-cert7","18.9-cert8","18.9-cert8\\-rc1","18.9-cert8\\-rc2","18.9-cert9","20.7-cert1","20.7-cert1\\-rc1","20.7-cert1\\-rc2","20.7-cert2","20.7-cert3","20.7-cert4","20.7-cert5","20.7-cert6","Asterisk \u003c= 20.15.0","Asterisk \u003c= 21.10.0","Asterisk \u003c= 22.5.0","Asterisk \u003c=18.26.2","20.15.0","20.15.0-rc3","20.15.0-rc1","20.15.0-rc2","20.14.0","21.10.0","21.10.0-rc3","21.10.0-rc1","21.10.0-rc2","21.9.0","22.5.0","22.5.0-rc3","22.5.0-rc1","22.5.0-rc2","22.4.0","certified-20.7-cert6","18.26.2","certified-20.7-cert5","certified-20.7-cert4","18.26.1","22.4.0-rc1","21.9.0-rc1","20.14.0-rc1","22.3.0","21.8.0","20.13.0","22.3.0-rc1","21.8.0-rc1","20.13.0-rc1","22.2.0","21.7.0","20.12.0","22.2.0-rc2","21.7.0-rc2","20.12.0-rc2","22.2.0-rc1","21.7.0-rc1","20.12.0-rc1","22.1.1","21.6.1","20.11.1","22.1.0","21.6.0","certified-20.7-cert3","20.11.0","18.26.0","18.26.0-rc1","22.1.0-rc1","21.6.0-rc1","20.11.0-rc1","22.0.0","21.5.0","20.10.0","18.25.0","18.25.0-rc2","20.10.0-rc2","21.5.0-rc2","21.5.0-rc1","20.10.0-rc1","18.25.0-rc1","21.4.3","20.9.3","18.24.3","certified-20.7-cert2","21.4.2","20.9.2","18.24.2","21.4.1","20.9.1","18.24.1","certified-20.7-cert1","18.24.0","20.9.0","21.4.0","21.4.0-rc1","20.9.0-rc1","18.24.0-rc1","certified-20.7-cert1-rc2","21.3.1","20.8.1","18.23.1","21.3.0","20.8.0","18.23.0","21.3.0-rc1","20.8.0-rc1","18.23.0-rc1","certified-20.7-cert1-rc1","certified-20.7-cert1-pre1","20.7.0","21.2.0","18.22.0","21.2.0-rc2","20.7.0-rc2","18.22.0-rc2","20.7.0-rc1","18.22.0-rc1","21.2.0-rc1","21.1.0","20.6.0","18.21.0","21.1.0-rc2","20.6.0-rc2","18.21.0-rc2","21.1.0-rc1","20.6.0-rc1","18.21.0-rc1","21.0.2","20.5.2","18.20.2","18.20.1","20.5.1","21.0.1","21.0.0","20.5.0","18.20.0","20.5.0-rc1","18.20.0-rc1","20.4.0","18.19.0","18.19.0-rc2","20.4.0-rc2","20.4.0-rc1","18.19.0-rc1","20.3.1","18.18.1","20.3.0","18.18.0","20.3.0-rc1","18.18.0-rc1","20.2.1","18.17.1","20.2.0","18.17.0","20.2.0-rc1","18.17.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1131.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/V:C/RE:H/U:Amber"}]}