CVE-2025-61035

The seffaflik thru 0.0.9 is vulnerable to symlink attacks due to incorrect default permissions given to the .kimlik file and .seffaflik file, which is created with mode 0777 and 0775 respectively, exposing secrets to other local users. Additionally, the .kimlik file is written without symlink checks, allowing local attackers to overwrite arbitrary files. This can result in information disclosure and denial of service.
Configurations

No configuration.

History

27 Oct 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7
CWE CWE-276

22 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-22 14:15

Updated : 2025-10-27 14:15


NVD link : CVE-2025-61035

Mitre link : CVE-2025-61035

CVE.ORG link : CVE-2025-61035


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions