CVE-2025-8522

Source
https://cve.org/CVERecord?id=CVE-2025-8522
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8522.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8522
Published
2025-08-04T19:02:05.798Z
Modified
2026-08-12T03:51:08.318949960Z
Severity
  • 1.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
givanz Vvvebjs node.js save.php path traversal
Details

A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown function of the file /save.php of the component node.js. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8522.json"
}
References

Affected packages

Git / github.com/givanz/vvvebjs

Affected ranges

Type
GIT
Repo
https://github.com/givanz/vvvebjs
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vvveb:vvvebjs:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        },
        {
            "introduced": "2.0.1"
        },
        {
            "last_affected": "2.0.1"
        },
        {
            "introduced": "2.0.2"
        },
        {
            "last_affected": "2.0.2"
        },
        {
            "introduced": "2.0.3"
        },
        {
            "last_affected": "2.0.3"
        },
        {
            "introduced": "2.0.4"
        },
        {
            "last_affected": "2.0.4"
        },
        {
            "introduced": "0"
        }
    ]
}

Affected versions

2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8522.json"