File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
References
| Link | Resource |
|---|---|
| https://www.agora-project.net | Product |
| https://www.helx.io/blog/advisory-agora-project/ | Third Party Advisory |
Configurations
History
21 Jan 2026, 14:42
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.agora-project.net - Product | |
| References | () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory | |
| CPE | cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:* | |
| First Time |
Agora-project
Agora-project agora-project |
15 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-15 16:16
Updated : 2026-01-21 14:42
NVD link : CVE-2025-67079
Mitre link : CVE-2025-67079
CVE.ORG link : CVE-2025-67079
JSON object : View
Products Affected
agora-project
- agora-project
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
