CVE-2025-6152

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:steel:browser:0.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.3:beta:*:*:*:*:*:*

History

02 Jul 2025, 19:47

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 02:15

Updated : 2025-07-02 19:47


NVD link : CVE-2025-6152

Mitre link : CVE-2025-6152

CVE.ORG link : CVE-2025-6152


JSON object : View

Products Affected

steel

  • browser
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')