We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-50202

Lychee Path Traversal Vulnerability



Description

Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has been patched in version 6.6.10.

Reserved 2025-06-13 | Published 2025-06-18 | Updated 2025-06-18 | Assigner GitHub_M


HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

>= 6.6.6, < 6.6.10
affected

References

github.com/...Lychee/security/advisories/GHSA-6rj9-gm78-vhf9

github.com/...ommit/ae7270b7b47e4a284ea1f69d260e52d592711072

github.com/.../app/Http/Controllers/SecurePathController.php

cve.org (CVE-2025-50202)

nvd.nist.gov (CVE-2025-50202)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-50202

Support options

Helpdesk Chat, Email, Knowledgebase