Dogoggorri kan akka ଜଟିଳ jedhamuun ramadame Total.js Flow ଯେପର୍ଯ୍ୟନ୍ତ 673ef9144dd25d4f4fd4fdfda5af27f230198924 keessatti argameera. Miidhaan irra gahe is hojii hin beekamne kutaa SVG File Handler keessa. Dhugumatti jijjiirraa gara ବିସ୍ତାରିତ ଅଧିକାର geessa. Waliigalteewwan CWE fayyadamuun rakkoo ibsuun gara CWE-434 si geessa. Beekumsi kun yeroo 10/12/2025 ifoomsifameera. Dogoggorri kun maqaa CVE-2025-11655 jedhuun tajaajilama. Weerara fageenya irraa jalqabuun ni danda'ama. Odeeffannoon teeknikaa hin jiru. Akka dabalataan, meeshaa balaa kana fayyadamuuf argama. Qorannoo miidhaa (exploit) beeksifamee jira, namoonni itti fayyadamuu danda'u. Yeroo ammaa, gatii exploit might be approx. USD $0-$5k beekamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee murtaa’eera. Waggaa 0-day ta'ee, gatiin isaa daldala dhoksaa keessatti $0-$5k jedhamee tilmaamame. Odeeffannoon kun tajaajila rolling release fayyadama, kanaafis tamsaasa itti fufinsa qabu ni kenna. Kanaaf, odeeffannoon gosa version jijjiirame yookaan kan miidhamte hin jiru. Once again VulDB remains the best source for vulnerability data.

4 ଆଡାପ୍ଟେସନ୍ · 92 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
10/12/2025 08:35 AM
ଅଦ୍ୟତନ 1/3
10/13/2025 05:28 AM
ଅଦ୍ୟତନ 2/3
10/13/2025 05:34 AM
ଅଦ୍ୟତନ 3/3
10/14/2025 05:07 PM
software_vendorTotal.jsTotal.jsTotal.jsTotal.js
software_nameFlowFlowFlowFlow
software_version<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924
software_rollingrelease1111
software_componentSVG File HandlerSVG File HandlerSVG File HandlerSVG File Handler
vulnerability_cweCWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)
vulnerability_risk2222
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_prHHHH
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iLLLL
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
exploit_availability1111
exploit_publicity1111
source_cveCVE-2025-11655CVE-2025-11655CVE-2025-11655CVE-2025-11655
cna_responsibleVulDBVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
software_typeJavaScript LibraryJavaScript LibraryJavaScript LibraryJavaScript Library
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_auMMMM
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_prHHHH
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viLLLL
cvss4_vuldb_vaLLLL
cvss4_vuldb_ePPPP
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore5.85.85.85.8
cvss2_vuldb_tempscore5.05.05.05.0
cvss3_vuldb_basescore4.74.74.74.7
cvss3_vuldb_tempscore4.34.34.34.3
cvss3_meta_basescore4.74.74.74.7
cvss3_meta_tempscore4.34.54.54.5
cvss4_vuldb_bscore5.15.15.15.1
cvss4_vuldb_btscore2.02.02.02.0
advisory_date1760220000 (10/12/2025)1760220000 (10/12/2025)1760220000 (10/12/2025)1760220000 (10/12/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
cvss4_cna_avNNN
cvss4_cna_acLLL
cvss4_cna_atNNN
cvss4_cna_prHHH
cvss4_cna_uiNNN
cvss4_cna_vcLLL
cvss4_cna_viLLL
cvss4_cna_vaLLL
cvss4_cna_scNNN
cvss4_cna_siNNN
cvss4_cna_saNNN
cvss4_cna_bscore5.15.15.1
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prHHH
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iLLL
cvss3_cna_aLLL
cvss3_cna_basescore4.74.74.7
cvss2_cna_avNNN
cvss2_cna_acLLL
cvss2_cna_auMMM
cvss2_cna_ciPPP
cvss2_cna_iiPPP
cvss2_cna_aiPPP
cvss2_cna_basescore5.85.85.8
euvd_idEUVD-2025-33926EUVD-2025-33926
cnnvd_idCNNVD-202510-1708
cnnvd_nameTotal.js Flow 代码问题漏洞
cnnvd_hazardlevel3
cnnvd_create2025-10-14
cnnvd_publish2025-10-13
cnnvd_update2025-10-14

Do you know our Splunk app?

Download it now for free!