CVE-2025-27106
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-27106 is a critical vulnerability affecting the binance-trading-bot, an automated Binance trading tool. Malicious authenticated users can exploit a command injection flaw in the `/restore` endpoint to execute arbitrary code on the host system. The vulnerability arises due to insufficient input validation for file names in the `/restore` endpoint's shell.exec function. This issue can lead to significant security risks, as any authorized user can execute code in the context of the host machine. Binance-trading-bot users are advised to upgrade to version 0.0.100 to mitigate this vulnerability, as there are currently no known workarounds.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.