← volver
CVE-2025-27519

Cognita Arbitrary File Write

CVSS 9.3 CRITICALEPSS 1.3%CWE-22
Vexday Risk Score
48Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 9.3EPSS 1.3%KEV nãoPoC públicaNuclei Metasploit Patch
Ciclo de vida
07 mar 2025Publicada en NVD
22 ago 2025PoC pública
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at /v1/internal/upload-to-local-directory which is enabled when the Local env variable is set to true, such as when Cognita is setup using Docker. Because the docker environment sets up the backend uvicorn server with auto reload enabled, when an attacker overwrites the /app/backend/__init__.py file, the file will automatically be reloaded and executed. This allows an attacker to get remote code execution in the context of the Docker container. This vulnerability is fixed in commit a78bd065e05a1b30a53a3386cc02e08c317d2243.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
truefoundry · cognita
PoCs públicas encontradas1
githubgithub.com/Diabl0xE/CVE-2025-275192
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.