CVE-2025-24971

CRITICAL

DumbDrop <commit 4ff8469d - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-24971. PoCs published by be4zad.

AI-analyzed exploit summary This PoC exploits a command injection vulnerability in DumbDrop by manipulating the filename parameter during file upload initialization. The payload is injected via the filename field, allowing arbitrary command execution on the target system.

Description

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, `/upload/init` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the **Apprise Notification** enabled. This issue has been addressed in commit `4ff8469d` and all users are advised to patch. There are no known workarounds for this vulnerability.

Exploits (1)

nomisec WORKING POC
by be4zad · poc
https://github.com/be4zad/CVE-2025-24971

This PoC exploits a command injection vulnerability in DumbDrop by manipulating the filename parameter during file upload initialization. The payload is injected via the filename field, allowing arbitrary command execution on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: DumbDrop (versions before commit 4ff8469)
Auth required
Prerequisites: DumbDrop server with APPRISE_URL enabled · Valid PIN for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.5
EPSS 0.0323
EPSS Percentile 86.6%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
DumbWareio/DumbDrop < 4ff8469d
Published Feb 04, 2025
Tracked Since Feb 18, 2026