Arbitrary Argument Injection Vulnerability in Cloudinary by Cloudinary
CVE-2025-12613
8.8HIGH
What is CVE-2025-12613?
Versions of Cloudinary prior to 2.7.0 are susceptible to Arbitrary Argument Injection due to inadequate handling of parameter values that include an ampersand. This flaw enables attackers to insert extra, unintended parameters, which may lead to severe consequences like bypassing security mechanisms, altering data integrity, or modifying the overall behavior of the application. This vulnerability highlights the importance of proper input validation and secure coding practices within application development.
Affected Version(s)
cloudinary 0 < 2.7.0
