v25.4.0 - 22 Apr 2025
This release includes new security checks and improvements.
New security checks
- Added a check for CrushFTP Authentication Bypass (CVE-2025-31161)
- Added a check for Ingress-Nginx “IngressNightmare” RCE (CVE-2025-1974)
- Added a check for Vite Arbitrary File Read (CVE-2025-30208, CVE-2025-31125)
- Added a check for Kentico Staging API Auth Bypass
Improvements
- Updated Node to version 20
- Updated OpenSSL to version 3.4.1
- Added an option to expose OpenSSL functions to sign or validate JWT tokens
- Added an option to disable the DAST scanner from exposing secrets
- Engine now uses Chromium 135.0.7049.41/52 for scanning