← volver
CVE-2025-27519criticalCWE-22

Cognita Arbitrary File Write

48Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 9.3epss 1.4%
de la publicación al arma168 días
Publicada en NVD7 mar
1ª PoC+168d
probabilidad de explotación
1.4%top 29% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at /v1/internal/upload-to-local-directory which is enabled when the Local env variable is set to true, such as when Cognita is setup using Docker. Because the docker environment sets up the backend uvicorn server with auto reload enabled, when an attacker overwrites the /app/backend/__init__.py file, the file will automatically be reloaded and executed. This allows an attacker to get remote code execution in the context of the Docker container. This vulnerability is fixed in commit a78bd065e05a1b30a53a3386cc02e08c317d2243.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
truefoundry · cognita
PoCs públicas encontradas1
githubgithub.com/Diabl0xE/CVE-2025-275192
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.