CVE-2025-53908

HIGH

RomM <3.10.3 & <4.0.0-beta.3 - Path Traversal

Title source: llm
STIX 2.1

Description

RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone running the latest version of RomM and has multiple users, even unprivileged users, such as the kiosk user in the official implementation, may be affected. This allows the leakage of passwords and users that may be stored on the system. Versions 3.10.3 and 4.0.0-beta.3 contain a patch.

Scores

CVSS v4 8.3
EPSS 0.0013
EPSS Percentile 31.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-26
Status published
Products (2)
rommapp/romm < 3.10.3
rommapp/romm < 4.0.0-beta.3
Published Jul 16, 2025
Tracked Since Feb 18, 2026