CVE-2025-23177

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 427

Summary

CVE-2025-23177 is a newly discovered vulnerability carrying a CWE-427 classification, specifically an uncontrolled search path element. This issue arises when a software application fails to properly validate user-supplied input that is used to construct file or directory paths. An attacker could leverage this flaw to execute arbitrary files, potentially leading to code execution with the privileges of the affected application. This vulnerability poses a serious risk, as it could result in system compromise or data exposure. Organizations are encouraged to apply relevant patches as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share