Directory Traversal Vulnerability in Robocode by Robo-Code
CVE-2025-14306

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-14306?

A significant directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The flawed implementation of the recursivelyDelete method does not sanitize file paths adequately, enabling an attacker to manipulate inputs to traverse directories and potentially delete arbitrary files on the system. By exploiting this vulnerability, malicious actors can execute unauthorized file deletions, posing serious risks to the integrity and availability of the system. Immediate action is recommended to mitigate this risk.

Affected Version(s)

Robocode Windows 1.9.3.6

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

.