We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-6152

Steel Browser files.routes.ts handleFileUpload path traversal



Description

EN DE

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.

Es wurde eine kritische Schwachstelle in Steel Browser bis 0.1.3 gefunden. Es geht dabei um die Funktion handleFileUpload der Datei api/src/modules/files/files.routes.ts. Durch das Manipulieren des Arguments filename mit unbekannten Daten kann eine path traversal-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Patch wird als 7ba93a10000fb77ee01731478ef40551a27bd5b9 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.

Reserved 2025-06-15 | Published 2025-06-17 | Updated 2025-06-17 | Assigner VulDB


MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
MEDIUM: 6.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
6.5AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C

Problem types

Path Traversal

Product status

0.1.0
affected

0.1.1
affected

0.1.2
affected

0.1.3
affected

Timeline

2025-06-15:Advisory disclosed
2025-06-15:VulDB entry created
2025-06-15:VulDB entry last update

Credits

VulDB GitHub Commit Analyzer tool

References

vuldb.com/?id.312627 (VDB-312627 | Steel Browser files.routes.ts handleFileUpload path traversal) vdb-entry technical-description

vuldb.com/?ctiid.312627 (VDB-312627 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.593060 (Submit #593060 | Steel Steel Browser <=0.1.3 Path Traversal) third-party-advisory

github.com/steel-dev/steel-browser/issues/129 issue-tracking

github.com/steel-dev/steel-browser/issues/129 issue-tracking

github.com/...ommit/7ba93a10000fb77ee01731478ef40551a27bd5b9 patch

cve.org (CVE-2025-6152)

nvd.nist.gov (CVE-2025-6152)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-6152

Support options

Helpdesk Chat, Email, Knowledgebase