CVE-2025-13699: MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the handling of view names. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13699?
CVE-2025-13699 is classified as a critical severity vulnerability that allows remote code execution.
How do I fix CVE-2025-13699?
To mitigate CVE-2025-13699, update MariaDB to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2025-13699?
Exploitation of CVE-2025-13699 can lead to unauthorized access and execution of arbitrary code on affected MariaDB systems.
Who is affected by CVE-2025-13699?
CVE-2025-13699 affects installations of the MariaDB database server that utilize the mariadb-dump utility.
Is there a workaround for CVE-2025-13699?
Currently, the recommended approach is to apply updates, as no specific workarounds have been detailed for CVE-2025-13699.