Ad

CVE-2026-25575

HIGH CVSS 4.0: 8.8 EPSS 0.03%
Updated Feb 05, 2026
NavigaTUM
Parameter Value
CVSS 8.8 (HIGH)
Type CWE-26, CWE-23 (Relative Path Traversal)
Vendor NavigaTUM
Public PoC No

NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in the propose_edits endpoint allows unauthenticated users to overwrite files in directories writable by the application user (e.g., /cdn). By supplying unsanitized file keys containing traversal sequences (e.g., ../../) in the JSON payload, an attacker can escape the intended temporary directory and replace public facing images or fill the server's storage.

This issue has been patched via commit 86f34c7.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0