PT-2025-25769 · Lychee · Lychee

Mrraul124

·

Published

2025-06-18

·

Updated

2025-06-23

·

CVE-2025-50202

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lychee versions 6.6.6 through 6.6.9
Description The issue affects Lychee, a free photo-management tool. An attacker can exploit a path traversal vulnerability in SecurePathController.php to leak local files, including environment variables, nginx logs, other users' uploaded images, and configuration secrets.
Recommendations For versions 6.6.6 through 6.6.9, update to version 6.6.10 to resolve the issue. As a temporary workaround, consider restricting access to the SecurePathController.php file until the update is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-50202
GHSA-6RJ9-GM78-VHF9

Affected Products

Lychee