CVE-2025-55988

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dreamfactory:dreamfactory_core:1.0.3:*:*:*:*:*:*:*

History

14 Apr 2026, 19:27

Type Values Removed Values Added
Summary
  • (es) Un problema en el componente /Controllers/RestController.php de DreamFactory Core v1.0.3 permite a los atacantes ejecutar un salto de directorio a través de una ruta URI no saneada.
References () https://github.com/dreamfactorysoftware/df-core/commit/54354605b2ec9afe6ee96756a5a22f6f56828950#diff-e57a7c0af25166ac8f02695307c6c413ca4ba0a48a20b2202ad910654528aab1 - () https://github.com/dreamfactorysoftware/df-core/commit/54354605b2ec9afe6ee96756a5a22f6f56828950#diff-e57a7c0af25166ac8f02695307c6c413ca4ba0a48a20b2202ad910654528aab1 - Patch
References () https://pentest-tools.com/PTT-2025-001-RemoteCodeExecution-via-URL-Path-Traversal.pdf - () https://pentest-tools.com/PTT-2025-001-RemoteCodeExecution-via-URL-Path-Traversal.pdf - Third Party Advisory
First Time Dreamfactory dreamfactory Core
Dreamfactory
CPE cpe:2.3:a:dreamfactory:dreamfactory_core:1.0.3:*:*:*:*:*:*:*

23 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

20 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 21:17

Updated : 2026-04-14 19:27


NVD link : CVE-2025-55988

Mitre link : CVE-2025-55988

CVE.ORG link : CVE-2025-55988


JSON object : View

Products Affected

dreamfactory

  • dreamfactory_core
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')