CVE Feed

    Dashboard / CVE / CVE-2025-6152

    CVE-2025-6152

    A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.

    Published:Jun 17, 2025
    Last Modified:Jul 2, 2025
    EPS:Jun 17, 2025
    EPSS Score:0.00103
    CVSS Score:6.3

    Affected Products

    Vendor
    Steel
    Product
    Browser

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High