← All CVEs

CVE-2025-46093

critical · 9.9

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

9.9
CVSS
0.5%
EPSS (exploit prob.)
44th
EPSS percentile
2025-08-04
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-732

Affected products

VendorProductAffected versions
liquidfilesliquidfiles< 4.1.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-46093