PT-2025-25504 · M Files · M-Files Server

Published

2025-06-10

·

Updated

2025-10-09

·

CVE-2025-5964

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/RE:M/U:Green
Name of the Vulnerable Software and Affected Versions M-Files Server versions prior to 25.6.14925.0
Description A path traversal issue in the API endpoint in M-Files Server allows an authenticated user to read files in the server.
Recommendations For versions prior to 25.6.14925.0, update to version 25.6.14925.0 or later to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-06794
CVE-2025-5964

Affected Products

M-Files Server