Path traversal in DOMPurify - CVE-2025-48050

 

Path traversal in DOMPurify - CVE-2025-48050

Published: August 20, 2025


Vulnerability identifier: #VU114312
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48050
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to scripts/server.js does not ensure that a pathname is located under the current working directory. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

DOMPurify
IBM Concert Software
IBM Security QRadar Log Management AQL Plugin
IBM Fusion HCI
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Pak for Business Automation
watsonx Orchestrate Developer Edition
DB2 Data Management Console
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
Data Product Hub
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Fedora
nextcloud

How to mitigate CVE-2025-48050

Install updates from vendor's website.

IBM Concert Software - update to 2.0.0
IBM Security QRadar Log Management AQL Plugin - update to 1.1.3
watsonx Orchestrate Developer Edition - update to 1.13.0
IBM Fusion HCI - update to 2.11.0
DB2 Data Management Console - update to 3.1.13.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.2.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Knowledge Catalog Premium Cartridge - update to 5.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
Data Product Hub - update to 5.2.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF004, 25.0.0-IF001
nextcloud - addressed in versions 31.0.5-1.fc41, 31.0.5-1.fc42, 31.0.5-1.fc43

External References

Related Security Bulletins