PT-2026-28339 · Bludit · Bludit
Arkadiusz Marta
·
Published
2026-03-27
·
Updated
2026-03-27
·
CVE-2026-25099
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bludit versions prior to 3.18.4
Description
The API plugin in Bludit allows a user with a valid API token to upload files of any type and extension without restriction. Successful exploitation of this issue can lead to Remote Code Execution. The API endpoint used for file upload does not properly validate the uploaded file's type or extension, allowing an attacker to upload and execute malicious files. The vulnerable parameter is the file itself, uploaded through the API.
Recommendations
Update to version 3.18.4 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit