VDB

CVE-2025-54141

CVE-2025-54141 PUBLISHED CVSS 7.5 HIGH

ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesystem though a directory traversal-style attack. This is fixed in versions 1.1.31 and 1.2.4.

EPSS 0.82% · 53.9th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.82%
53.9th percentile

Affected Products

VendorProductVersions
viewvcviewvc>= 1.1.0, < 1.1.31, 1.1.0, *

Timeline

  • Jan 21, 1970 Security Advisory
  • Jul 22, 2025 Coalition ESS Score
  • Jul 22, 2025 CVE Published
  • Jul 23, 2025 EPSS Score
  • Jul 23, 2025 CVE Updated
  • Jul 25, 2025 Coalition ESS Score
  • Aug 1, 2025 EPSS Score
  • Aug 5, 2025 Coalition ESS Score
  • Aug 10, 2025 EPSS Score
  • Aug 19, 2025 EPSS Score
  • Aug 22, 2025 Coalition ESS Score
  • Aug 26, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›