info: name: SawtoothSoftware Lighthouse Studio <9.16.14 – Pre‑Auth Remote Code Execution author: assetnote,DhiyaneshDK,iamnoooob severity: critical description: | A pre-authentication remote code execution vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14. The issue arises from the unsafe use of the `eval` function within the Perl CGI component `ciwweb.pl`, where attacker-supplied input inside `hid_Random_ACARAT` is directly passed to `eval`. This allows remote unauthenticated attackers to execute arbitrary Perl code on the server. reference: - https://slcyber.io/assetnote-security-research-center/rce-in-the-most-popular-survey-software-youve-never-heard-of/ - https://sawtoothsoftware.com/resources/software-downloads/lighthouse-studio metadata: verified:true max-request:1 shodan-query: html:"Lighthouse Studio" tags: cve,cve2025,lighthouse-studio,sawtoothsoftware,rce,ssti