Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8r2-47rx-qhw4

Опубликовано: 09 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 10

Описание

Robocode vulnerable to Directory Traversal in recursivelyDelete Method

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions.

Пакеты

Наименование

net.sf.robocode:robocode.core

maven
Затронутые версииВерсия исправления

< 1.9.5.6

1.9.5.6

EPSS

Процентиль: 63%
0.01074
Низкий

10 Critical

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
ubuntu
9 месяцев назад

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

CVSS3: 9.1
nvd
9 месяцев назад

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

CVSS3: 9.1
debian
9 месяцев назад

A directory traversal vulnerability exists in the CacheCleaner compone ...

EPSS

Процентиль: 63%
0.01074
Низкий

10 Critical

CVSS4

Дефекты

CWE-22