PT-2025-48723 · Grapesjs · Grapesjs

Jan Linhart

+2

·

Published

2025-12-02

·

Updated

2025-12-05

·

CVE-2025-13827

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GrapesJS (affected versions not specified)
Description The GrapesJS Builder allows the upload of arbitrary files due to a lack of file type restrictions. If the media folder is not configured to prevent file execution, this could lead to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13827
GHSA-5XW2-57JX-PGJP

Affected Products

Grapesjs