Security Advisory: MITRE Caldera Dynamic Compilation RCE (CVE-2025-27364)

ISGroup Cybersecurity

MITRE Caldera is an adversary emulation platform whose agents – specifically Sandcat and Manx – are dynamically compiled at the time of download. All versions of Caldera released before commit 35bc06e (including older versions) are vulnerable.
This vulnerability becomes exploitable when the target system has Go, Python, and gcc installed – dependencies generally required for the full functionality of Caldera. On many distributions, installing Go also involves installing gcc, further increasing exposure.

ProductCaldera Framework
Date2025-03-10 14:47:04
Information
  • Trending
  • Fix Available

Technical Summary

The vulnerability resides in the dynamic compilation functionality used by Caldera agents. When an agent is requested, the server dynamically compiles a custom binary by injecting user-controllable parameters (such as communication methods, encryption keys, and callback addresses) into the linker flags. The main issue is the insecure handling of these linker flags — specifically through the use of options like -X (similar to -D in gcc), as well as the dangerous -extld and -extldflags flags.

Although compilation is performed via subprocess.check_output() without shell=True (which mitigates some direct injection risks), an attacker can still manipulate the compilation process by abusing linker flags. By setting an external linker (such as gcc or clang) and passing attacker-controlled arguments via -extldflags, it is possible to execute arbitrary commands during the build process.

A proof-of-concept (PoC) has demonstrated how appropriately crafted values in HTTP headers can trigger this behavior, leading to remote code execution on vulnerable systems.

Recommendations

  • Update immediately:
    Upgrade to a patched version of MITRE Caldera (the latest version of the Master branch or v5.1.0 and later) which resolves this vulnerability.

  • Restrict network access:
    Allow access to the Caldera server only from trusted hosts, reducing the risk of unauthorized exploits.

  • Harden build environments:
    Remove or restrict unnecessary compilation tools (Go, Python, gcc) on production systems, or isolate the Caldera server in a controlled environment.

  • Monitor and audit:
    Increase monitoring and logging levels to detect anomalous activity that could indicate exploit attempts. Regularly verify configuration and access controls on dynamic compilation endpoints.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert