← back
CVE-2025-14306

Directory Traversal in Robocode's CacheCleaner Component

CVSS 10 CRITICALEPSS 0.9%CWE-22
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 10EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →