
CVE-2025-27591
belowThis repository contains an exploit for CVE-2025-27591, a privilege escalation vulnerability in the Linux monitoring tool Below.
below (prior to v0.9.0)/var/log/below/error_root.log) as root, allowing symlink attacks by unprivileged users.This exploit allows a local user to escalate privileges to root by:
/var/log/below/error_root.log to /etc/passwdbelow to write to the symlink/etc/passwdbelow is available via sudo, e.g.:sudo -l
(ALL : ALL) NOPASSWD: /usr/bin/below *