CVE-2025-5964: Path traversal in M-Files API
Published Jun 15, 2025
·Updated
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
Affected Software
4 affected components
M-Files M-Files server<25.6.14925.0
M-Files M-Files server<24.8.13981.16
M-Files M-Files server>=25.2.14524.3<25.2.14524.9
M-Files M-Files server>=25.3.14681.7<25.6.14925.0
Remediation
Information
Update to the latest patched version.
Event History
Jun 15, 2025
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5964?
CVE-2025-5964 is classified as a medium severity vulnerability due to its impact on file access within the M-Files Server.
2
How do I fix CVE-2025-5964?
To fix CVE-2025-5964, upgrade the M-Files Server to version 25.6.14925.0 or later.
3
Who is affected by CVE-2025-5964?
CVE-2025-5964 affects all authenticated users of M-Files Server versions prior to 25.6.14925.0.
4
What type of vulnerability is CVE-2025-5964?
CVE-2025-5964 is a path traversal vulnerability that allows unauthorized file access.
5
Can CVE-2025-5964 be exploited remotely?
CVE-2025-5964 requires an authenticated user, meaning it cannot be exploited remotely without valid credentials.