VYPR
Medium severity5.3NVD Advisory· Published Sep 19, 2025· Updated Jun 17, 2026

CVE-2025-56869

CVE-2025-56869

Description

Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Sync In server/Sync In serverdescription
  • Sync In/Serverllm-fuzzy2 versions
    <=1.1.1+ 1 more
    • (no CPE)range: <=1.1.1
    • cpe:2.3:a:sync-in:sync-in_server:*:*:*:*:*:*:*:*range: <=1.1.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.