CVE-2025-67810

MEDIUM

Area9lyceum Rhapsode - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0002
EPSS Percentile 4.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
area9lyceum/rhapsode 1.47.3
Published Jan 09, 2026
Tracked Since Feb 18, 2026