CVE-2025-50735: Path Traversal
Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50735?
CVE-2025-50735 is considered a high severity vulnerability due to the potential for unauthorized disclosure of sensitive information.
How do I fix CVE-2025-50735?
To fix CVE-2025-50735, upgrade NextChat to version 2.16.1 or later where the vulnerability has been addressed.
What does CVE-2025-50735 affect?
CVE-2025-50735 affects NextChat versions up to but not including 2.16.1, where a directory traversal vulnerability exists in the WebDAV proxy.
Can CVE-2025-50735 be exploited without authentication?
Yes, CVE-2025-50735 can be exploited via both authenticated and anonymous WebDAV endpoints, increasing its risk.
What are the implications of CVE-2025-50735?
The implications of CVE-2025-50735 include the risk of attackers accessing sensitive files on the server due to improper input validation.