CVE-2025-32779
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 15, 2025
CWE ID 22
Summary
CVE-2025-32779 is a vulnerability affecting E.D.D.I's (Enhanced Dialog Driven Interface) API endpoint in versions prior to 5.5.0. An attacker can exploit a Zip Slip vulnerability in the `/backup/import` API, allowing them to write arbitrary files outside the intended extraction directory. Although the application runs as a non-root user, this vulnerability can be used to overwrite application files, including JAR libraries, potentially leading to Remote Code Execution within the application's context. This issue has been remedied in version 5.5.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- E.D.D.I
Affected Vendors
- Labsai