← Back to Resources
Open Source NewsOctober 3, 20252 min read

CVE-2025-49844 "RediShell" Critical RCE Disclosed

By BIOS Founding Team

CVE-2025-49844 "RediShell" Critical RCE Disclosed

Wiz Research disclosed a maximum-severity authenticated remote-code-execution flaw in Redis's Lua scripting engine, a 13-year-old use-after-free bug triggerable via a crafted Lua script, prompting urgent patch guidance and ACL-based mitigations.

Full details: https://redis.io/blog/security-advisory-cve-2025-49844/