We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-6283

xataio Xata Agent route.ts GET path traversal



Description

EN DE

A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the function GET of the file apps/dbagent/src/app/api/evals/route.ts. The manipulation of the argument passed leads to path traversal. Upgrading to version 0.3.1 is able to address this issue. The patch is named 03f27055e0cf5d4fa7e874d34ce8c74c7b9086cc. It is recommended to upgrade the affected component.

Es wurde eine Schwachstelle in xataio Xata Agent bis 0.3.0 ausgemacht. Sie wurde als problematisch eingestuft. Es geht dabei um die Funktion GET der Datei apps/dbagent/src/app/api/evals/route.ts. Durch das Manipulieren des Arguments passed mit unbekannten Daten kann eine path traversal-Schwachstelle ausgenutzt werden. Ein Aktualisieren auf die Version 0.3.1 vermag dieses Problem zu lösen. Der Patch wird als 03f27055e0cf5d4fa7e874d34ce8c74c7b9086cc bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.

Reserved 2025-06-19 | Published 2025-06-19 | Updated 2025-06-19 | Assigner VulDB


MEDIUM: 5.1CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
LOW: 3.5CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C
LOW: 3.5CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C
2.7AV:A/AC:L/Au:S/C:P/I:N/A:N/E:ND/RL:OF/RC:C

Problem types

Path Traversal

Product status

0.1
affected

0.2
affected

0.3.0
affected

0.3.1
unaffected

Timeline

2025-06-19:Advisory disclosed
2025-06-19:VulDB entry created
2025-06-19:VulDB entry last update

Credits

VulDB GitHub Commit Analyzer tool

References

vuldb.com/?id.313287 (VDB-313287 | xataio Xata Agent route.ts GET path traversal) vdb-entry technical-description

vuldb.com/?ctiid.313287 (VDB-313287 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.593627 (Submit #593627 | xataio Xata Agent < 0.3.1 Arbitrary File Read) third-party-advisory

github.com/xataio/agent/issues/179 issue-tracking

github.com/xataio/agent/pull/191 issue-tracking

github.com/...ommit/03f27055e0cf5d4fa7e874d34ce8c74c7b9086cc patch

github.com/xataio/agent/releases/tag/v0.3.1 patch

cve.org (CVE-2025-6283)

nvd.nist.gov (CVE-2025-6283)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-6283

Support options

Helpdesk Chat, Email, Knowledgebase