A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/upload of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 4e93ac86d4891c59ecfcd27c051de9b3c5379315. It is recommended to upgrade the affected component.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6466.json",
"cwe_ids": [
"CWE-284",
"CWE-434"
],
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"last_affected": "2.0.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.0.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:ageerle:ruoyi-ai:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6466.json"
"2026-07-22T04:02:43Z"
[
{
"digest": {
"line_hashes": [
"148087044969352381056275867828545735805",
"34725913395536423916349751125207691743",
"162286769192361504396089996019921640973",
"298372522933321206652190675621021381319",
"250835505832207916461702692271195650406",
"15432646037208711942849860436305303057",
"129794773033183252325790234393549131191",
"1177915342719120647746310218083244811",
"238288556527101316291872464136973208233",
"79935805022576660383786666391805950448",
"153934448360081512314889547541280000471",
"162377256447167593847115879820189597160"
],
"threshold": 0.9
},
"id": "CVE-2025-6466-0a658b2f",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/4e93ac86d4891c59ecfcd27c051de9b3c5379315",
"signature_type": "Line",
"target": {
"file": "ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java"
}
},
{
"digest": {
"function_hash": "219797390937233428290398827141535940433",
"length": 422.0
},
"id": "CVE-2025-6466-453a4d77",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/4e93ac86d4891c59ecfcd27c051de9b3c5379315",
"signature_type": "Function",
"target": {
"function": "speechToTextTranscriptionsV2",
"file": "ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java"
}
},
{
"digest": {
"line_hashes": [
"74458364718597976167491101028698699250",
"175758554031635119792633184596069700822",
"298843258647431689255760792766112066263",
"145903898021235776646211378589092764952",
"201688554390376815622184313920908172143",
"309268553102925634606131265804781666877",
"222854370824423845438804674698003008149",
"166552475406659008308966925298852240492"
],
"threshold": 0.9
},
"id": "CVE-2025-6466-6168eca0",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/4e93ac86d4891c59ecfcd27c051de9b3c5379315",
"signature_type": "Line",
"target": {
"file": "ruoyi-common/ruoyi-common-core/src/main/java/org/ruoyi/common/core/utils/file/MimeTypeUtils.java"
}
},
{
"digest": {
"line_hashes": [
"283546586693771569642354098009633013813",
"235358149465883840531758308628939771750",
"277121855913105872701497894733373211273",
"160398779371343553221005021871176189224",
"189491751992891881654870343992507600630",
"259551517183874887658502738804595811340"
],
"threshold": 0.9
},
"id": "CVE-2025-6466-7c610e54",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/6382e177bf90cc56ff70521842409e35c50df32d",
"signature_type": "Line",
"target": {
"file": "ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java"
}
},
{
"digest": {
"line_hashes": [
"44949252518822031026692676250955886026",
"31611881945461421717074460037727552565",
"124107902882977043196064040149104475063",
"108348730618602177680056855712329545794",
"334202244419594554206416883489001107176",
"1586399528177458842483752016098611483",
"253730525076372644439920905330053419205",
"84993949745860530779962376608322423989",
"237696491364065587487169034941221779993",
"281919865404749307581059368163680915642"
],
"threshold": 0.9
},
"id": "CVE-2025-6466-9dad08f9",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/4e93ac86d4891c59ecfcd27c051de9b3c5379315",
"signature_type": "Line",
"target": {
"file": "ruoyi-common/ruoyi-common-core/src/main/java/org/ruoyi/common/core/utils/file/FileUtils.java"
}
},
{
"digest": {
"function_hash": "332765050994421529927438085576555793110",
"length": 159.0
},
"id": "CVE-2025-6466-ac8cf52a",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/ageerle/ruoyi-ai/commit/4e93ac86d4891c59ecfcd27c051de9b3c5379315",
"signature_type": "Function",
"target": {
"function": "upload",
"file": "ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java"
}
}
]