CVE-2025-67079

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de carga de archivos en Omnispace Agora Project anterior a 25.10 permitiendo a los atacantes ejecutar código a través del motor MSL de la biblioteca Imagick mediante un archivo PDF manipulado a las funciones de carga de archivos y miniaturas.

21 Jan 2026, 14:42

Type Values Removed Values Added
References () https://www.agora-project.net - () https://www.agora-project.net - Product
References () https://www.helx.io/blog/advisory-agora-project/ - () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory
CPE cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*
First Time Agora-project
Agora-project agora-project

15 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 16:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67079

Mitre link : CVE-2025-67079

CVE.ORG link : CVE-2025-67079


JSON object : View

Products Affected

agora-project

  • agora-project
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type