CVE-2025-6282

MEDIUM

xlang OpenAgents < 2024-11-18 - Path Traversal in create_upload_file Function

Title source: llm
STIX 2.1

Description

A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is the function create_upload_file of the file backend/api/file.py. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The reported GitHub issue was closed automatically with the label "not planned" by a bot.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.313286
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.313286
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.593616
Exploit, Issue Tracking exploit issue-tracking
https://github.com/xlang-ai/OpenAgents/issues/141

Scores

CVSS v3 5.5
EPSS 0.0058
EPSS Percentile 42.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
xlang/openagents < 2024-11-18
Published Jun 19, 2025
Tracked Since Feb 18, 2026