SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-14306

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6.

CRITICAL 10.0EPSS 1.07%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

CVSS 4.0
10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
1.07% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
robocode/robocode
Source
cve_disclosure@tech.gov.sg

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.