VDB

GCVE-110-CLOUD-2025-0038

GCVE-110-CLOUD-2025-0038
Advisory Published
Vulnetix · Advisory published April 9, 2025
A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.

Affected Products

VendorProductVersionsPlatforms
AWSSSM

Browse GCVE Records

74,265 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›