CVE-2025-56365: Matter Sdk Misplaced Validateclusterpath
Validating cluster paths using `Ember::ValidateClusterPath` within `Invoke` methods at the DataModelProvider layer is structurally insufficient and can lead to a reachable assertion (CVE-2025-56365) in `ProcessCommandDataIB` when invalid endpoints are processed. The validation check has been shifted to the caller to ensure invalid endpoints are securely reje
greprules fetch cve-2025-56365-matter-sdk-misplaced-validateclusterpath --engine opengrepDescription
Validating cluster paths using `Ember::ValidateClusterPath` within `Invoke` methods at the DataModelProvider layer is structurally insufficient and can lead to a reachable assertion (CVE-2025-56365) in `ProcessCommandDataIB` when invalid endpoints are processed. The validation check has been shifted to the caller to ensure invalid endpoints are securely reje
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.