rowboatlabs rowboat Session route.ts PUT missing authentication
Published Jul 7, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.44%
Description
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the component Session Handler. The manipulation of the argument params leads to missing authentication. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. It is expected that this issue will be fixed in the near future.
Affected products
-
Affected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rowboatlabs | Rowboat | unknown | Affected |
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20194 Advisory
- https://github.com/rowboatlabs/rowboat/issues/166 issue-tracking
- https://github.com/rowboatlabs/rowboat/issues/166#issuecomment-2995195594 issue-tracking
- https://vuldb.com/?ctiid.315026 signaturepermissions-required
- https://vuldb.com/?id.315026 vdb-entrytechnical-description
- https://vuldb.com/?submit.604899 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-20194 | Advisory | |
| https://github.com/rowboatlabs/rowboat/issues/166 | issue-tracking | |
| https://github.com/rowboatlabs/rowboat/issues/166#issuecomment-2995195594 | issue-tracking | |
| https://vuldb.com/?ctiid.315026 | signaturepermissions-required | |
| https://vuldb.com/?id.315026 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.604899 | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data