Directory Traversal Remote Code Execution Vulnerability in MariaDB Utility
CVE-2025-13699

7HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-13699?

The directory traversal vulnerability in the MariaDB mariadb-dump utility allows remote attackers to execute arbitrary code on affected installations. The flaw arises from inadequate validation of user-supplied paths when handling view names, enabling attackers to manipulate file operations to execute malicious code in the context of the current user.

Affected Version(s)

MariaDB 11.8.3

References

CVSS V3.0

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.