Critical severity9.9NVD Advisory· Published Aug 4, 2025· Updated Jun 17, 2026
CVE-2025-46093
CVE-2025-46093
Description
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*range: <4.1.2
- (no CPE)range: <4.1.2
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
3- projectblack.io/blog/liquidfiles-vulnerability-authenticated-rce/nvdExploitThird Party Advisory
- gist.github.com/nikolai0x/f61a8bfcdaa244e0c46931d74d10c4eanvdThird Party Advisory
- docs.liquidfiles.com/release_notes/version_4-1-x.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.