CVE-2025-2954
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13.
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.17% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266, CWE-284
- Affected
- mannaandpoem/openmanus
- Source
- cna@vuldb.com
References
- https://magnificent-dill-351.notion.site/Arbitrary-File-Writing-in-OpenManus-2025-3-13-1b9c693918ed805e8e7fd35a896d2d41Broken Link
- https://vuldb.com/?ctiid.302007Permissions Required, VDB Entry
- https://vuldb.com/?id.302007Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.521545Third Party Advisory, VDB Entry
- https://magnificent-dill-351.notion.site/Arbitrary-File-Writing-in-OpenManus-2025-3-13-1b9c693918ed805e8e7fd35a896d2d41Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.