ShowDoc - Remote Code Execution
CVE-2025-0520
Verified
Description
The open-source API documentation tool ShowDoc had a remote code execution vulnerability before version 2.8.7 This vulnerability allowed unauthenticated remote attackers to upload .php files because the image upload function was not authenticated and the file extension validation was improper.
Severity
Critical
CVSS Score
9.4
Exploit Probability
3%
Affected Product
showdoc
Published Date
August 13, 2026
Template Author
pikpikcu, co5mos, papbutfly
CVE-2025-0520.yaml
9.4Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
CVE ID:
cve-2025-0520
CWE ID:
cwe-434
Remediation Steps
Please update ShowDoc to version 2.8.7 or higher to fix this vulnerability.