Логотип exploitDog
bind:CVE-2025-12613
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12613

Количество 2

Количество 2

nvd логотип

CVE-2025-12613

3 месяца назад

Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior. **Note:** Following our established security policy, we attempted to contact the maintainer regarding this vulnerability, but haven't received a response.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-g4mf-96x5-5m2c

3 месяца назад

Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12613

Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior. **Note:** Following our established security policy, we attempted to contact the maintainer regarding this vulnerability, but haven't received a response.

CVSS3: 8.6
0%
Низкий
3 месяца назад
github логотип
GHSA-g4mf-96x5-5m2c

Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand

CVSS3: 8.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу