CVE-2025-0733

CVSS 3.1 Score 4.5 of 10 (medium)

Details

Published Jan 27, 2025
CWE ID 426

Summary

CVE-2025-0733 is a recently identified vulnerability in Postman up to version 11.20 for Windows. This issue lies within the profapi.dll library and permits an attacker to manipulate untrusted search paths, posing a risk. The attack must be executed locally and is considered complex due to the high level of difficulty in exploitation. Despite early disclosure, the vendor has yet to respond to the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share