CVE-2025-65112 is a critical vulnerability affecting ricardoboss PubNet versions prior to 1.1.3. It allows unauthenticated attackers to upload packages as any user by manipulating the author-id in the /api/storage/upload endpoint. This flaw enables identity spoofing, privilege escalation, and supply chain attacks. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 96/100, indicating a very high risk. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community attention with one mention, highlighting its potential impact. Users are urged to patch to version 1.1.3 or higher immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.4CPE matchmatch criteria | cpe:2.3:a:ricardoboss:pubnet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.