CVE-2025-27092
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-27092 is a path traversal vulnerability affecting the open source user simulation framework, GHOSTS, version 8.0.0.0. This issue is found in the /api/npcs/{id}/photo endpoint, which is intended to serve profile photos for Non-Player Characters (NPCs). However, the application fails to properly validate and sanitize file paths, allowing an attacker to traverse directories and access files outside of the intended photo directory. This could potentially expose sensitive system files, including configuration files, credentials, or other data, with the permissions of the web application process. Version 8.2.7.90 has addressed this vulnerability, and all users are advised to upgrade as soon as possible. There are currently no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.