Unrated severityNVD Advisory· Published Sep 25, 2025· Updated Sep 26, 2025
CVE-2025-29157
CVE-2025-29157
Description
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
Affected products
1- petstore/petstoredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.