CVE-2025-27410
Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content.
Does this matter?
Lower severity and a low EPSS score (2.11%). Track it; it rarely justifies an emergency change on its own.
Description
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their content. By overwriting an included `.js` file and restarting the container, this allows for Remote Code Execution as an administrator. The remote code execution occurs because any user with the `backups:create` and `backups:update` (only administrators by default) is able to overwrite any file on the system. Version 1.2.0 fixes the issue.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-23
- Affected
- pwndoc project/pwndoc
- Source
- security-advisories@github.com
References
- https://github.com/pwndoc/pwndoc/blob/14acb704891245bf1703ce6296d62112e85aa995/backend/src/routes/backup.js#L527Product
- https://github.com/pwndoc/pwndoc/commit/98f284291d73d3a0b11d3181d845845c192d1080Patch
- https://github.com/pwndoc/pwndoc/releases/tag/v1.2.0Release Notes
- https://github.com/pwndoc/pwndoc/security/advisories/GHSA-mxw8-vgvx-89hxExploit, Vendor Advisory
- https://github.com/pwndoc/pwndoc/security/advisories/GHSA-mxw8-vgvx-89hxExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.