CVE-2025-8344 is a critical unrestricted file upload vulnerability affecting openviglet shio versions up to 0.3.8. Specifically, the shStaticFileUpload function in ShStaticFileAPI.java allows remote attackers to upload arbitrary files by manipulating the filename argument. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, the exploit has been publicly disclosed, and there is significant community discussion, indicating a high potential for exploitation despite no known active exploits or readily available Metasploit/Nuclei modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.8CPE matchmatch criteria | cpe:2.3:a:viglet:shio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.