CVE-2025-32779
MEDIUMEDDI < 5.5.0 - Path Traversal and Arbitrary File Write via Backup Import Endpoint
Title source: llmDescription
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to the `/backup/import` API endpoint can write arbitrary files to locations outside the intended extraction directory due to a Zip Slip vulnerability. Although the application runs as a non-root user (`185`), limiting direct impact on system-level files, this vulnerability can still be exploited to overwrite application files (e.g., JAR libraries) owned by the application user. This overwrite can potentially lead to Remote Code Execution (RCE) within the application's context. This issue has been patched in version 5.5.0.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/labsai/EDDI/security/advisories/GHSA-9v34-frgq-63mv
Patch x_refsource_misc
https://github.com/labsai/EDDI/commit/1e207d0e4f72a5a93920bc0f76cad53ffd8e7065
Various Sources x_refsource_misc
https://www.sonarsource.com/blog/code-security-for-conversational-ai-uncovering-a-zip-slip-in-eddi
Scores
CVSS v3
6.5
EPSS
0.0100
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (1)
labsai/EDDI
< 5.5.0
Published
Apr 15, 2025
Tracked Since
Feb 18, 2026