Metrics
Affected Vendors & Products
Wed, 02 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Steel
Steel browser |
|
CPEs | cpe:2.3:a:steel:browser:0.1.1:beta1:*:*:*:*:*:* cpe:2.3:a:steel:browser:0.1.2:beta:*:*:*:*:*:* cpe:2.3:a:steel:browser:0.1.3:beta:*:*:*:*:*:* |
|
Vendors & Products |
Steel
Steel browser |
Tue, 17 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue. | |
Title | Steel Browser files.routes.ts handleFileUpload path traversal | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-17T01:31:05.835Z
Updated: 2025-06-17T14:19:20.164Z
Reserved: 2025-06-15T18:43:35.926Z
Link: CVE-2025-6152

Updated: 2025-06-17T14:19:13.452Z

Status : Analyzed
Published: 2025-06-17T02:15:20.213
Modified: 2025-07-02T19:47:02.363
Link: CVE-2025-6152

No data.