CVE-2025-6152

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. The patch is named 7ba93a10000fb77ee01731478ef40551a27bd5b9. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:steel:browser:0.1.1:beta1:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.3:beta:*:*:*:*:*:*

History

02 Jul 2025, 19:47

Type Values Removed Values Added
CPE cpe:2.3:a:steel:browser:0.1.3:beta:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.2:beta:*:*:*:*:*:*
cpe:2.3:a:steel:browser:0.1.1:beta1:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Steel
Steel browser
References () https://github.com/steel-dev/steel-browser/issues/129#issuecomment-2936052240 - () https://github.com/steel-dev/steel-browser/issues/129#issuecomment-2936052240 - Exploit, Issue Tracking
References () https://vuldb.com/?submit.593060 - () https://vuldb.com/?submit.593060 - Third Party Advisory, VDB Entry
References () https://github.com/steel-dev/steel-browser/issues/129 - () https://github.com/steel-dev/steel-browser/issues/129 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.312627 - () https://vuldb.com/?ctiid.312627 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.312627 - () https://vuldb.com/?id.312627 - Third Party Advisory, VDB Entry
References () https://github.com/steel-dev/steel-browser/commit/7ba93a10000fb77ee01731478ef40551a27bd5b9 - () https://github.com/steel-dev/steel-browser/commit/7ba93a10000fb77ee01731478ef40551a27bd5b9 - Patch

17 Jun 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : unknown
CWE CWE-22

17 Jun 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 02:15

Updated : 2025-07-02 19:47


NVD link : CVE-2025-6152

Mitre link : CVE-2025-6152


JSON object : View

Products Affected

steel

  • browser
CWE

No CWE.