Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

0Xvpr

#19123of 53,624
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-38236
6.2
2025-09-17
Zimaos · Zimaos · CVE-2025-58431
**Name of the Vulnerable Software and Affected Versions** ZimaOS versions prior to 1.4.2 **Description** ZimaOS, a fork of CasaOS, is susceptible to a file read issue. The `/v2 1/files/file/download` API endpoint allows unauthorized file access from any user with localhost access. File reads are executed with root privileges. **Recommendations** Update ZimaOS to version 1.4.2 or later. As a temporary workaround, restrict access to the `/v2 1/files/file/download` endpoint.
PT-2025-38241
7.8
2025-09-17
Casaos · Casaos · CVE-2025-58432
**Name of the Vulnerable Software and Affected Versions** ZimaOS versions prior to 1.4.1 **Description** ZimaOS, a fork of CasaOS, is susceptible to a file upload issue. The `/v2 1/files/file/uploadV2` API endpoint permits file uploads from any user with localhost access, and these uploads are executed with root privileges. **Recommendations** Update ZimaOS to version 1.4.1 or later.