{"id":"CVE-2025-13261","aliases":["GHSA-5jpg-2rj5-964c"],"url":"https://o3.security/vulnerability/CVE-2025-13261","summary":"lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal","details":"A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.","published":"2025-11-17T03:32:05.193Z","modified":"2026-07-15T01:49:18.155417897Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"lsfusion.platform:web-client","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13261.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13261"},{"type":"ADVISORY","url":"https://vuldb.com/?id.332596"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.689412"},{"type":"REPORT","url":"https://github.com/lsfusion/platform/issues/1543"},{"type":"REPORT","url":"https://github.com/lsfusion/platform/issues/1543#issue-3576922131"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.332596"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:18.155417897Z"}}