VYPR
Medium severity5.3NVD Advisory· Published Jan 2, 2026· Updated Jul 14, 2026

CVE-2025-34171

CVE-2025-34171

Description

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which reveals installed applications and configuration details. Additionally, /v1/sys/debug discloses host operating system, kernel, hardware, and storage information. The endpoints also return distinct error messages, enabling file existence enumeration of arbitrary paths on the underlying host filesystem. This information disclosure can be used for reconnaissance and to facilitate targeted follow-up attacks against services deployed on the host.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:*
    Range: <=0.4.15
  • CasaOS/CasaOSllm-fuzzy
    Range: <=0.4.15
  • IceWhale Tech/CasaOSv5
    Range: 0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.