CVE-2025-66386: Path Traversal
Published Nov 28, 2025
·Updated
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
Affected Software
1 affected component
Misp Misp<2.5.27
Event History
Nov 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66386?
CVE-2025-66386 has a medium severity level due to the potential for path traversal attacks.
2
How do I fix CVE-2025-66386?
To fix CVE-2025-66386, upgrade MISP to version 2.5.27 or later.
3
What software is affected by CVE-2025-66386?
CVE-2025-66386 affects MISP versions prior to 2.5.27.
4
What type of vulnerability is CVE-2025-66386?
CVE-2025-66386 is classified as a path traversal vulnerability.
5
Who are the potential attackers for CVE-2025-66386?
The potential attackers for CVE-2025-66386 are site administrators of MISP who may be exploited through path traversal.