VulnerabilityAnalyzed
CVE-2025-46093
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
HIGH 8.8EPSS 0.53%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- liquidfiles/liquidfiles
- Source
- cve@mitre.org
References
- https://docs.liquidfiles.com/release_notes/version_4-1-x.htmlRelease Notes
- https://gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4eaThird Party Advisory
- https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/Exploit, Third Party Advisory
- https://projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.