High severity8.8NVD Advisory· Published Jan 15, 2026· Updated Jun 17, 2026
CVE-2025-67077
CVE-2025-67077
Description
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*range: <25.10
- (no CPE)range: <25.10
- Omnispace/Agora Projectdescription
- Range: <25.10
- Range: <25.10
Patches
Vulnerability mechanics
References
2- www.helx.io/blog/advisory-agora-project/nvdThird Party Advisory
- www.agora-project.netnvdProduct
News mentions
0No linked articles in our index yet.