CVE-2025-51056

HIGH

Vedo Suite <2024.17 - RCE

Title source: llm
STIX 2.1

Description

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).

Scores

CVSS v3 8.2
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
vedo_suite_project/vedo_suite 2024.17
Published Aug 06, 2025
Tracked Since Feb 18, 2026