/Vulnerability Library

WhoDB < 0.45.0 - Path Traversal

CVE-2025-24786
Verified

Description

WhoDB contains a path traversal caused by lack of validation when opening database files, letting unauthenticated attackers access arbitrary Sqlite3 databases on the host system, exploit requires attacker to manipulate database filename input.

Severity

High

CVSS Score

7.5

Exploit Probability

3%

Affected Product

whodb

Published Date

February 1, 2026

Template Author

basicbeny

CVE-2025-24786.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-24786
CWE ID:
cwe-22

References

https://github.com/clidey/whodbhttps://github.com/clidey/whodb/security/advisories/GHSA-9r4c-jwx3-3j76https://nvd.nist.gov/vuln/detail/CVE-2025-24786

Remediation Steps

Upgrade to version 0.45.0 or later.