CVE-2025-2954

CVSS 3.1 Score 7 of 10 (high)

Details

Published Mar 30, 2025
Updated: Apr 15, 2025
CWE ID 476

Summary

CVE-2025-2954 is a vulnerability affecting mannaandpoem OpenManus up to version 2025.3.13. The issue lies in the execute function of the File Handler component's app/tool/file_saver.py file. This vulnerability results in improper access controls, granting attackers local access to potentially exploit the system. Though the exploit has been made public, the vendor has not provided a response regarding the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share