PT-2025-25769 · Lychee · Lychee
Mrraul124
·
Published
2025-06-18
·
Updated
2025-06-23
·
CVE-2025-50202
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lychee versions 6.6.6 through 6.6.9
Description
The issue affects Lychee, a free photo-management tool. An attacker can exploit a path traversal vulnerability in SecurePathController.php to leak local files, including environment variables, nginx logs, other users' uploaded images, and configuration secrets.
Recommendations
For versions 6.6.6 through 6.6.9, update to version 6.6.10 to resolve the issue. As a temporary workaround, consider restricting access to the SecurePathController.php file until the update is applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lychee