Back

HIGH

XBMC ≤ 11.0 Web Server Path Traversal

Published Aug 5, 2025

Description

XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authenticated users to request files outside the intended document root. An attacker can exploit this flaw to read arbitrary files from the host filesystem, including sensitive configuration or credential files.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 5, 2025
Updated Jul 15, 2026
Reserved Aug 5, 2025
CISA Vulnrichment
Updated Jun 2, 2026
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a