PT-2025-16363 · E.D.D.I · E.D.D.I

Paul-Gerste-Sonarsource

·

Published

2025-04-15

·

Updated

2025-10-27

·

CVE-2025-32779

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions E.D.D.I versions prior to 5.5.0
Description The issue is related to a Zip Slip vulnerability in the E.D.D.I middleware, which connects and manages LLM API bots. An attacker with access to the "/backup/import" API endpoint can write arbitrary files to locations outside the intended extraction directory. Although the application runs as a non-root user, limiting direct impact on system-level files, this vulnerability can still be exploited to overwrite application files, such as JAR libraries, owned by the application user. This overwrite can potentially lead to Remote Code Execution (RCE) within the application's context.
Recommendations For versions prior to 5.5.0, update to version 5.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the "/backup/import" API endpoint to minimize the risk of exploitation. Additionally, restricting access to the vulnerable middleware components can help mitigate the risk until a patch is applied.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32779
GHSA-9V34-FRGQ-63MV

Affected Products

E.D.D.I