CVE-2025-13008: Session Token Disclosure in M-Files Web
Published Dec 19, 2025
·Updated
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
Affected Software
1 affected component
M-Files M-Files server<25.12.15491.7, <25.8, <25.2, <24.8
Remediation
Information
Update M-Files Server to unaffected version.
Event History
Dec 19, 2025
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-13008?
CVE-2025-13008 is classified as an information disclosure vulnerability.
2
How do I fix CVE-2025-13008?
To fix CVE-2025-13008, upgrade M-Files Server to version 25.12.15491.8 or later, or to 25.8 LTS SR4 or later.
3
What versions of M-Files Server are affected by CVE-2025-13008?
CVE-2025-13008 affects M-Files Server versions prior to 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3, and 24.8 LTS SR5.
4
Who can exploit CVE-2025-13008?
CVE-2025-13008 can be exploited by an authenticated attacker using M-Files Web.
5
What kind of information is disclosed in CVE-2025-13008?
CVE-2025-13008 allows the attacker to capture session tokens of other active users.