CVE-2025-6152

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.
Configurations

No configuration.

History

17 Jun 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad crítica en Steel Browser hasta la versión 0.1.3. Esta afecta a la función handleFileUpload del archivo api/src/modules/files/files.routes.ts. La manipulación del argumento filename provoca un path traversal. Es posible iniciar el ataque de forma remota. El parche se llama 7ba93a10000fb77ee01731478ef40551a27bd5b9. Se recomienda aplicar un parche para solucionar este problema.
References () https://github.com/steel-dev/steel-browser/issues/129 - () https://github.com/steel-dev/steel-browser/issues/129 -

17 Jun 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 02:15

Updated : 2025-06-17 20:50


NVD link : CVE-2025-6152

Mitre link : CVE-2025-6152

CVE.ORG link : CVE-2025-6152


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')