CVE-2025-35430
CVE-2025-35430 is a medium-severity vulnerability in Cisa Thorium with a CVSS 3.x base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.0)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (39th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-29738
- Weakness: CWE-22
- Affected product: Cisa Thorium
- Published:
- Last modified:
Description
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.
Frequently asked questions
- What is CVE-2025-35430?
- CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.
- How severe is CVE-2025-35430?
- CVE-2025-35430 has a CVSS 3.x base score of 5.0, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2025-35430 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (39th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-35430?
- CVE-2025-35430 affects Cisa Thorium. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-35430?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-35430 have an EU (EUVD) identifier?
- Yes. CVE-2025-35430 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-29738.
- When was CVE-2025-35430 published?
- CVE-2025-35430 was published on 2025-09-17 and last updated on 2026-06-17.
References
- https://github.com/cisagov/thorium/blob/main/api/src/utils/bounder.rs#L120-L158
- https://github.com/cisagov/thorium/releases/tag/1.1.2
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-259-01.json
- https://www.cve.org/CVERecord?id=CVE-2025-35430
Affected products (1)
- cpe:2.3:a:cisa:thorium:*:*:*:*:*:*:*:*
More vulnerabilities in Cisa Thorium
- CVE-2025-35431 — Medium (CVSS 5.4): CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify…
- CVE-2025-35436 — Medium (CVSS 5.3): CISA Thorium uses '.unwrap()' to handle errors related to account verification email messages. An unauthenticated…
- CVE-2025-35432 — Medium (CVSS 5.3): CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated…
- CVE-2025-35433 — Medium (CVSS 5.0): CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a…
- CVE-2025-35435 — Medium (CVSS 4.3): CISA Thorium accepts a stream split size of zero then divides by this value. A remote, authenticated attacker could…
- CVE-2025-35434 — Medium (CVSS 4.2): CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with…
All CVEs affecting Cisa Thorium →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.