/Vulnerability Library

ShowDoc - Remote Code Execution

CVE-2025-0520
Verified

Description

The open-source API documentation tool ShowDoc had a remote code execution vulnerability before version 2.8.7 This vulnerability allowed unauthenticated remote attackers to upload .php files because the image upload function was not authenticated and the file extension validation was improper.

Severity

Critical

CVSS Score

9.4

Exploit Probability

3%

Affected Product

showdoc

Published Date

August 13, 2026

Template Author

pikpikcu, co5mos, papbutfly

CVE-2025-0520.yaml
9.4Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
CVE ID:
cve-2025-0520
CWE ID:
cwe-434

References

https://nvd.nist.gov/vuln/detail/CVE-2025-0520https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585https://github.com/star7th/showdoc/pull/1059https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585

Remediation Steps

Please update ShowDoc to version 2.8.7 or higher to fix this vulnerability.