PT-2026-26674 · Dreamfactory · Dreamfactory/Df-Core

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2025-55988

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DreamFactory Core version 1.0.3
Description An issue exists in the /Controllers/RestController.php component that allows attackers to execute a directory traversal due to an unsanitized URI path. The vulnerable component processes requests without proper validation of the provided path, potentially allowing unauthorized access to files and directories. The API endpoint involved is likely related to resource access through the REST controller. The vulnerable parameter is the URI path used in requests to this endpoint.
Recommendations Update DreamFactory Core to a version that addresses this issue. As a temporary workaround, restrict access to the /Controllers/RestController.php component to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-55988
GHSA-GV7F-W92J-383Q

Affected Products

Dreamfactory/Df-Core