CVE-2025-66908 describes an improper file type validation vulnerability in the Turms AI-Serving module v0.10.0-SNAPSHOT and earlier. The OCR image upload functionality fails to properly enforce image file restrictions, relying only on client-provided Content-Type headers and file extensions without validating actual file content. This medium-severity vulnerability (CVSS 5.3) allows an unauthenticated attacker to upload arbitrary file types, including executables or web shells, by manipulating the Content-Type header or file extension. Such a bypass could lead to server-side code execution, stored cross-site scripting (XSS), or information disclosure. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.10.0-snapshotCPE matchmatch criteria | cpe:2.3:a:turms-im:turms:0.10.0-snapshot:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.