RediShell RCE Vulnerability
What is the Vulnerability? | A Use-After-Free (UAF) bug in Redis’s Lua scripting subsystem (tracked as CVE-2025-49844, “RediShell”) allows an authenticated attacker who can run Lua scripts to escape the Lua sandbox and achieve arbitrary native code execution on the Redis host. |
What is the recommended Mitigation? |
|
What FortiGuard Coverage is available? |
|
Additional Resources
Redis Security Advisory: CVE-2025-49844
GitHub Security Advisory
How does Lacework FortiCNAPP Protect from... - Fortinet Community