CVE-2025-8343

MEDIUM

viglet shio < 0.3.8 - Path Traversal via ShStaticFilePreUpload Function

Title source: llm
STIX 2.1

Description

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.318293
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.318293
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.617679
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://github.com/openviglet/shio/issues/1028
Exploit, Issue Tracking, Vendor Advisory exploit issue-tracking
https://github.com/openviglet/shio/issues/1028#issue-3239418750

Scores

CVSS v3 4.3
EPSS 0.0079
EPSS Percentile 51.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
viglet/shio < 0.3.8
Published Jul 31, 2025
Tracked Since Feb 18, 2026