CVE-2025-11233 is a medium-severity path traversal vulnerability affecting Rust versions 1.87.0 to 1.88.0 when compiled for the tier 3 Cygwin target (x86_64-pc-cygwin). The standard library's Path API on this specific target incorrectly handled backslash path separators, potentially leading to path traversal attacks or malicious filesystem operations in applications that validate paths. This vulnerability primarily impacts users who manually compiled the Cygwin target, as pre-built binaries are not distributed. The CVSS score of 6.3 (Medium) indicates a network-exploitable vulnerability with low attack complexity, potentially leading to low impacts on confidentiality, integrity, and availability. However, its practical impact is limited due to the niche compilation target. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Rust Project | Std | >= 1.87.0, < 1.89.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:Green
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.