CVE-2025-67810
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
09/01/2026
Last modified:
09/01/2026
Description
In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



