Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8r2-47rx-qhw4

Опубликовано: 09 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 10

Описание

Robocode vulnerable to Directory Traversal in recursivelyDelete Method

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions.

Пакеты

Наименование

net.sf.robocode:robocode.core

maven
Затронутые версииВерсия исправления

< 1.9.5.6

1.9.5.6

EPSS

Процентиль: 68%
0.0056
Низкий

10 Critical

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

CVSS3: 9.1
nvd
2 месяца назад

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

CVSS3: 9.1
debian
2 месяца назад

A directory traversal vulnerability exists in the CacheCleaner compone ...

EPSS

Процентиль: 68%
0.0056
Низкий

10 Critical

CVSS4

Дефекты

CWE-22