CVE-2025-67442
HIGHEVE-NG 6.4.0-13-PRO - Authenticated Directory Traversal via Export API
Title source: llmDescription
EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://github.com/XunMInt/cve/blob/main/EVE-NG_20251207.md
Scores
CVSS v3
7.6
EPSS
0.0048
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
eve-ng/eve-ng
6.4.0-13
Published
Dec 19, 2025
Tracked Since
Feb 18, 2026