CVE-2025-6283 Information
Description
A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the function GET of the file apps/dbagent/src/app/api/evals/route.ts. The manipulation of the argument passed leads to path traversal. Upgrading to version 0.3.1 is able to address this issue. The patch is named 03f27055e0cf5d4fa7e874d34ce8c74c7b9086cc. It is recommended to upgrade the affected component.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/xataio/agent/commit/03f27055e0cf5d4fa7e874d34ce8c74c7b9086cc https://github.com/xataio/agent/issues/179 https://github.com/xataio/agent/pull/191 https://github.com/xataio/agent/releases/tag/v0.3.1 https://vuldb.com/?ctiid.313287 https://vuldb.com/?id.313287 https://vuldb.com/?submit.593627
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.5
Related CNNVD
CNNVD-202506-2609 (Published: 2025-06-19)
Share on: