CVE-2025-4613

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
12/06/2025
Last modified:
01/08/2025

Description

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:web_designer:*:*:*:*:*:*:*:* 16.3.0.0407 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*