Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6152

Опубликовано: 17 июн. 2025
Источник: nvd
CVSS3: 6.3
CVSS3: 9.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:steel:browser:0.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.3:beta:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00128
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.3
github
8 месяцев назад

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.

EPSS

Процентиль: 33%
0.00128
Низкий

6.3 Medium

CVSS3

9.8 Critical

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22