Arbitrary File Access Vulnerability in Atheos Cloud IDE
CVE-2025-22152
Currently unrated
What is CVE-2025-22152?
Atheos, a self-hosted cloud IDE application, is vulnerable due to inadequate validation of the $path and $target parameters in various PHP components prior to version 600. This flaw can be exploited by attackers to read, modify, or execute arbitrary files on the server, leading to potential data breaches and unauthorized access. The vulnerability exists across multiple entry points within the application, making it crucial for users to update to version 600 or later to mitigate the associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Atheos < 600
