Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-15637 is an unauthenticated local file inclusion (LFI) vulnerability affecting Shuffle versions 1.8 and earlier. This vulnerability allows attackers to read arbitrary files from the affected system without authentication, potentially exposing sensitive configuration files, API keys, database credentials, and other critical data. Shuffle is a workflow automation platform used by security teams for incident response and threat intelligence operations, making it an attractive target. Organizations running vulnerable Shuffle instances face immediate risk of information disclosure that could lead to lateral movement, privilege escalation, or further compromise of connected security tools and infrastructure.
While this CVE lacks mapped MITRE ATT&CK techniques and is not yet in CISA's Known Exploited Vulnerabilities catalog, Casky's platform would detect attack patterns associated with reconnaissance and credential access through its extensive skill library. Practitioners using Casky would observe findings related to CWE-98 (Input Validation failure) patterns, including detection of path traversal sequences ("../", "..\\") in HTTP requests to Shuffle endpoints, unusual file access requests targeting configuration directories, and attempts to retrieve files outside intended application scope. Extended reasoning through Claude AI would correlate unauthenticated access attempts with file enumeration patterns, flagging suspicious request chains that indicate active exploitation. Security teams would see behavioral indicators such as rapid sequential requests to different file paths, successful HTTP 200 responses returning file contents, and access patterns targeting known sensitive file locations—enabling rapid identification and containment before data exfiltration occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-15637. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation