Medium severity5.3NVD Advisory· Published Nov 17, 2025· Updated Jun 17, 2026
CVE-2025-13261
CVE-2025-13261
Description
A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lsfusion.platform:web-clientMaven | <= 6.1 | — |
Affected products
3- lsfusion/platformv5Range: 6.0
Patches
Vulnerability mechanics
References
7- github.com/lsfusion/platform/issues/1543nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/lsfusion/platform/issues/1543nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-5jpg-2rj5-964cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-13261ghsaADVISORY
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdThird Party AdvisoryVDB EntryWEB
- vuldb.comnvdPermissions RequiredVDB EntryWEB
News mentions
0No linked articles in our index yet.