PT-2025-45601 · Cloudinary · Cloudinary

Patryk Konior

·

Published

2025-11-10

·

Updated

2025-11-14

·

CVE-2025-12613

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions cloudinary versions prior to 2.7.0
Description The package is susceptible to Arbitrary Argument Injection because of improper parsing of parameter values that include an ampersand (&). This allows an attacker to inject additional, unintended parameters. This could lead to malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior.
Recommendations Update to version 2.7.0 or later.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2025-12613
GHSA-G4MF-96X5-5M2C

Affected Products

Cloudinary