CVE-2026-25099
Remote Code Execution via Unrestricted File Upload in Bludit
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 1.9%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
27 Mar 2026Published on NVD
07 May 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution.
This issue was fixed in 3.18.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Affected products
Bludit · Bluditpublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52553unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →