High severity8.2NVD Advisory· Published Aug 6, 2025· Updated Jul 5, 2026
CVE-2025-51056
CVE-2025-51056
Description
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Vedo Suite/Vedo Suitedescription
- Range: = 2024.17
- Range: = 2024.17
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.