VDB
CVE-2025-54141
CVE-2025-54141
PUBLISHED
CVSS 7.5 HIGH
ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC distribution can expose the contents of the host server's filesystem though a directory traversal-style attack. This is fixed in versions 1.1.31 and 1.2.4.
EPSS 0.82% · 53.9th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.82%
53.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| viewvc | viewvc | >= 1.1.0, < 1.1.31, 1.1.0, * |
Timeline
- Jan 21, 1970 Security Advisory
- Jul 22, 2025 Coalition ESS Score
- Jul 22, 2025 CVE Published
- Jul 23, 2025 EPSS Score
- Jul 23, 2025 CVE Updated
- Jul 25, 2025 Coalition ESS Score
- Aug 1, 2025 EPSS Score
- Aug 5, 2025 Coalition ESS Score
- Aug 10, 2025 EPSS Score
- Aug 19, 2025 EPSS Score
- Aug 22, 2025 Coalition ESS Score
- Aug 26, 2025 Coalition ESS Score