CVE-2025-24786 is a critical path traversal vulnerability affecting WhoDB versions prior to 0.45.0, an open-source SQLite database management tool. An unauthenticated attacker can exploit this flaw to access any SQLite database on the host system by manipulating the database file path. With a CVSS score of 9.1 (CRITICAL), this vulnerability allows for high confidentiality and integrity impact without user interaction. While not currently in the KEV catalog or actively exploited, Nuclei templates exist for detection, and immediate upgrade to version 0.45.0 is strongly advised as there are no known workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.45.0CPE matchmatch criteria | cpe:2.3:a:clidey:whodb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.