PT-2025-49798 · Unknown · Static Web Server

Published

2025-12-09

·

Updated

2025-12-11

·

CVE-2025-67487

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Static Web Server versions 2.40.0 and below
Description Static Web Server (SWS) is a web server designed for static web files. Versions 2.40.0 and below do not adequately prevent symbolic links (symlinks) from being used to access files and directories outside the intended web root folder. A malicious actor who gains access to the web server’s root directory can create symlinks to access other files outside the designated web root folder, either through a URL or by using directory listings.
Recommendations Update to version 2.40.1 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67487
GHSA-459F-X8VQ-XJJM

Affected Products

Static Web Server