PT-2025-48209 · Dreamfactory+1 · Dreamfactory+1

Alexandru Postolache

+2

·

Published

2025-11-26

·

Updated

2025-12-24

·

CVE-2025-13700

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DreamFactory (affected versions not specified)
Description A flaw exists in the implementation of the saveZipFile method that could allow remote attackers to execute arbitrary code on affected DreamFactory installations. Authentication is required for exploitation. The issue stems from insufficient validation of user-supplied input before it is used in a system call, potentially allowing an attacker to execute code with the privileges of the service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13700
ZDI-25-1024

Affected Products

Dreamfactory
Df-Core