CVE-2025-27092 is a path traversal vulnerability in GHOSTS version 8.0.0.0, an open-source user simulation framework. An unauthenticated attacker can exploit the /api/npcs/{id}/photo endpoint by crafting a malicious photoLink value to access arbitrary files outside the intended directory. This high-severity vulnerability (CVSS 7.5) allows for unauthorized information disclosure, potentially exposing sensitive system files and credentials. There are no known active exploits, public exploit code, or significant community discussion, but users are advised to upgrade to version 8.2.7.90 immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.2.7.90CPE matchmatch criteria | cpe:2.3:a:cmu:ghosts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.