Medium severity6.1NVD Advisory· Published Jun 13, 2025· Updated Jun 17, 2026
CVE-2025-46096
CVE-2025-46096
Description
Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.noear:solon-faas-luffyMaven | >= 3.1.2, < 3.2.0 | 3.2.0 |
Affected products
3- solon/solon-faas-luffydescription
Patches
Vulnerability mechanics
References
5- github.com/opensolon/solon/issues/357nvdExploitIssue TrackingThird Party AdvisoryWEB
- gist.github.com/yaoyao-cool/1b7d80930fea88b6fd4839646cedc437nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-m63q-4hr8-5r5hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-46096ghsaADVISORY
- github.com/opensolon/solon/commit/49a3bf95fdcf050829843004b65a2b336ca6ddffghsaWEB
News mentions
0No linked articles in our index yet.