MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
CVE-2025-13699

7HIGH

Key Information:

Vendor

Mariadb

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-13699?

MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MariaDB. Interaction with the mariadb-dump utility is required to exploit this vulnerability but attack vectors may vary depending on the implementation.

The specific flaw exists within the handling of view names. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27000.

Affected Version(s)

MariaDB 11.8.3

References

CVSS V3.0

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-13699 : Directory Traversal Remote Code Execution Vulnerability in MariaDB Utility