CVE-2025-35430: CISA Thorium insecure downloaded file path validation
Published Sep 17, 2025
·Updated
CISA Thorium does not adequately validate the paths of downloaded files via 'downloadephemeral' and 'downloadchildren'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.
Affected Software
2 affected components
CISA Thorium<1.1.2
CISA Thorium>=1.0.0<1.1.2
Event History
Sep 17, 2025
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-35430?
CVE-2025-35430 has a moderate severity level due to its potential for unauthorized file access.
2
How do I fix CVE-2025-35430?
To fix CVE-2025-35430, upgrade to CISA Thorium version 1.1.2 or higher.
3
Who is affected by CVE-2025-35430?
Users of CISA Thorium versions prior to 1.1.2 are affected by CVE-2025-35430.
4
What does CVE-2025-35430 exploit?
CVE-2025-35430 exploits the inadequate validation of file paths when downloading files, allowing access to arbitrary files.
5
Is CVE-2025-35430 a remote vulnerability?
Yes, CVE-2025-35430 is a remote vulnerability that requires authenticated access to exploit.