Medium severity6.5NVD Advisory· Published Sep 25, 2025· Updated Jun 17, 2026
CVE-2025-29157
CVE-2025-29157
Description
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:smartbear:swagger_petstore:1.0.7:*:*:*:*:*:*:*
- petstore/petstoredescription
- Range: <=1.0.7
Patches
Vulnerability mechanics
References
2- gist.github.com/HouqiyuA/3c36f78e8de9f6a3cfb0959477c07443nvdExploitThird Party Advisory
- petstore3.swagger.ionvdProduct
News mentions
0No linked articles in our index yet.