CVE-2026-25575

HIGH

Navigatum < 2026-02-03 - Path Traversal

Title source: rule
STIX 2.1

Description

NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in the propose_edits endpoint allows unauthenticated users to overwrite files in directories writable by the application user (e.g., /cdn). By supplying unsanitized file keys containing traversal sequences (e.g., ../../) in the JSON payload, an attacker can escape the intended temporary directory and replace public facing images or fill the server's storage. This issue has been patched via commit 86f34c7.

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 18.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-26 CWE-23 CWE-22
Status published
Products (1)
tum/navigatum < 2026-02-03
Published Feb 04, 2026
Tracked Since Feb 18, 2026