Unrated severityNVD Advisory· Published Jan 15, 2026· Updated Jan 16, 2026
CVE-2025-67077
CVE-2025-67077
Description
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.
Affected products
2- Omnispace/Agora Projectdescription
- Range: <25.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.