CVE-2025-0733
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Jan 27, 2025
CWE ID 426
Summary
CVE-2025-0733 is a recently identified vulnerability in Postman up to version 11.20 for Windows. This issue lies within the profapi.dll library and permits an attacker to manipulate untrusted search paths, posing a risk. The attack must be executed locally and is considered complex due to the high level of difficulty in exploitation. Despite early disclosure, the vendor has yet to respond to the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Postman
Affected Vendors
- Postman, Inc.