CVE-2025-2954
CVSS 3.1 Score 7 of 10 (high)
Details
Published Mar 30, 2025
Updated: Apr 15, 2025
CWE ID 476
Summary
CVE-2025-2954 is a vulnerability affecting mannaandpoem OpenManus up to version 2025.3.13. The issue lies in the execute function of the File Handler component's app/tool/file_saver.py file. This vulnerability results in improper access controls, granting attackers local access to potentially exploit the system. Though the exploit has been made public, the vendor has not provided a response regarding the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.