PT-2025-47547 · Unknown · Dreampie Resty

Sh7Err

·

Published

2025-11-20

·

Updated

2025-11-24

·

CVE-2025-13435

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dreampie Resty versions up to 1.3.1.SNAPSHOT
Description A security issue exists in Dreampie Resty. Manipulation of the filename argument within the Request function, located in the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the HttpClient Module, can lead to a path traversal condition. This issue is considered highly complex to exploit, but the exploit has been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions prior to 1.3.1.SNAPSHOT should be used. As a temporary workaround, consider restricting access to the Request function until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-13435
GHSA-CV3M-HXPC-4HVM

Affected Products

Dreampie Resty