PT-2026-6324 · Navigatum · Navigatum

Gebhartleopold-Coder

·

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2026-25575

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NavigaTUM versions prior to commit 86f34c7
Description NavigaTUM is a website and API used for searching locations. A path traversal flaw exists in the propose edits API endpoint, allowing unauthenticated users to overwrite files in directories accessible to the application user, such as /cdn. This is achieved by providing unsanitized file keys containing traversal sequences (e.g., ../../) within the JSON payload, enabling attackers to bypass the intended temporary directory and potentially replace public images or exhaust server storage.
API Endpoints /propose edits
Vulnerable Parameters or Variables file keys (within the JSON payload)
Recommendations Update NavigaTUM to commit 86f34c7 or later.

Exploit

Fix

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-25575
GHSA-59HJ-F48W-HJFM

Affected Products

Navigatum