CVE-2025-5964

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
15/06/2025
Last modified:
09/10/2025

Description

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* 24.8.13981.16 (excluding)
cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* 25.2.14524.3 (including) 25.2.14524.9 (excluding)
cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:* 25.3.14681.7 (including) 25.6.14925.0 (excluding)


References to Advisories, Solutions, and Tools