CVE-2025-53709 affects the Secure-upload data submission service, which is installed in a limited number of environments. This vulnerability allows privileged users to select incorrect email templates and redirect submission channels to their controlled datasets. Additionally, unauthenticated users could enumerate existing enrollments and resource IDs across enrollments. The vulnerability is rated Medium severity with a CVSS score of 5.4, indicating low attack complexity and requiring low privileges. Successful exploitation could lead to low confidentiality and integrity impacts, but no availability impact. The FAUCET Risk Score is 42/100. There is no evidence of active exploitation, nor is there any publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, consistent with the majority of CVEs. The affected service has been patched with version 0.815.0 and automatically deployed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Palantir | Com.Palantir.Secupload:Secure-Upload | < 0.815.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.