A 13-year-old critical remote code execution (RCE) vulnerability in Redis , known as RediShell , allows attackers to gain full access to the underlying host system. The flaw, tracked as CVE-2025-49844 , was discovered by Wiz Research and has received the highest possible CVSS severity rating of 10.0 , a rating reserved for the most serious security issues.
See also: Use-after-free vulnerability in Redis Server allows RCE

The vulnerability is a Use-After-Free (UAF) that has existed in the Redis source code for about 13 years. A post-authentication attacker can exploit this flaw by sending a specially crafted Lua script. Because Lua execution is a default feature, the attacker can escape the Lua sandbox environment to achieve arbitrary code execution on the Redis host.
This level of access gives the attacker complete control, allowing them to steal, delete, or encrypt data, seize system resources for activities such as cryptocurrency mining, and move laterally through the network. The potential impact is magnified by the ubiquity of Redis. It is estimated that 75% of cloud environments use the in-memory data store for caching, session management, and messaging.
See also: Vulnerability in SolarWinds Web Help Desk allows RCE execution

The combination of this critical vulnerability with common development practices that often lack proper security hardening creates a significant risk multiplier for organizations worldwide. The analysis by Wiz Research revealed an extensive attack surface, with approximately 330,000 Redis instances exposed on the internet. Alarmingly, about 60,000 of these instances do not have authentication configured. The official Redis container image, which represents 57% of cloud deployments, does not require authentication by default.
This configuration is extremely dangerous, as it allows any unauthenticated attacker to send malicious Lua scripts and execute code in the environment. Even examples that are exposed only to internal networks are at high risk, as an attacker with an initial foothold could exploit the vulnerability for lateral movement to more sensitive systems. The attack flow starts with the attacker sending a malicious Lua script to the vulnerable Redis instance.
After successfully exploiting the UAF bug to escape the sandbox, the attacker can create a reverse shell for persistent access. From there, they can compromise the entire hosting system by stealing credentials such as SSH keys and IAM tokens, installing malicious software, and exfiltrating sensitive data from both Redis and the host machine.
See also: Critical vulnerabilities in Chaos Mesh allow RCE attacks

On October 3, 2025, Redis released a security advisory and patch releases to address CVE-2025-49844. All Redis users are strongly urged to upgrade their versions immediately, prioritizing those exposed to the internet or lacking authentication. In addition to the fix, organizations should implement best practices for security hardening.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
