CVE-2025-67124
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
23/01/2026
Last modified:
23/01/2026
Description
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary files outside the intended upload/document root in deployments where the attacker can create/replace filesystem entries in the upload destination directory (e.g., shared writable directory/volume).
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM



