CVE-2025-14306

CRITICAL

Robocode < 1.9.5.6 - Path Traversal and Arbitrary File Deletion via CacheCleaner recursivelyDelete Method

Title source: llm
STIX 2.1

Description

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

Scores

CVSS v3 9.1
EPSS 0.0090
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
net.sf.robocode/robocode.core 0 - 1.9.5.6Maven
robocode/robocode 1.9.3.6
Published Dec 09, 2025
Tracked Since Feb 18, 2026