A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 15 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mannaandpoem
Mannaandpoem openmanus
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mannaandpoem:openmanus:*:*:*:*:*:*:*:*
Vendors & Products Mannaandpoem
Mannaandpoem openmanus

Mon, 31 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 30 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title mannaandpoem OpenManus File file_saver.py execute access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-30T16:31:05.242Z

Updated: 2025-03-31T13:04:26.725Z

Reserved: 2025-03-29T19:39:01.052Z

Link: CVE-2025-2954

cve-icon Vulnrichment

Updated: 2025-03-31T13:04:12.800Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-30T17:15:19.890

Modified: 2025-04-15T17:57:44.213

Link: CVE-2025-2954

cve-icon Redhat

No data.