Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal. v602 contains a fix for the issue.
History

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 15 May 2025 19:45:00 +0000

Type Values Removed Values Added
Description Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal. v602 contains a fix for the issue.
Title Missing Path Validation Enables Path Traversal in Controller.php
Weaknesses CWE-22
CWE-23
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-15T19:40:58.761Z

Updated: 2025-05-19T14:43:37.687Z

Reserved: 2025-05-09T19:49:35.622Z

Link: CVE-2025-47788

cve-icon Vulnrichment

Updated: 2025-05-19T14:43:21.848Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-15T20:16:09.357

Modified: 2025-05-19T15:15:25.200

Link: CVE-2025-47788

cve-icon Redhat

No data.