VYPR
Unrated severityNVD Advisory· Published Sep 4, 2025· Updated Sep 4, 2025

Path Traversal vulnerability in appRain CMF

CVE-2025-41035

Description

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

Affected products

2
  • Apprain/Apprainllm-fuzzy
    Range: =4.0.5
  • appRain/appRain CMFv5
    Range: 4.0.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.