PT-2025-31466 · Unknown · Openviglet Shio
1098024193
·
Published
2025-07-31
·
Updated
2025-09-03
·
CVE-2025-8343
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openviglet shio versions through 0.3.8
Description
A critical vulnerability exists in openviglet shio up to version 0.3.8. This issue affects the
shStaticFilePreUpload function located in the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. Manipulation of the fileName argument leads to a path traversal vulnerability, allowing for remote attacks. The exploit for this issue has been publicly disclosed.Recommendations
Versions prior to 0.3.9 are affected.
As a temporary workaround, consider restricting access to the
shStaticFilePreUpload function until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openviglet Shio