Arbitrary File Read Vulnerability in SysmonElixir by Bocaletto
CVE-2025-52574
7.5HIGH
What is CVE-2025-52574?
Prior to version 1.0.1, the SysmonElixir HTTP service allowed unrestricted access to files on the server through its /read endpoint, exposing sensitive information such as the /etc/passwd file. The vulnerability has been addressed in version 1.0.1 by implementing a whitelist that restricts file access to directories specific to the application's data, significantly enhancing its security posture.
Affected Version(s)
elixir-system-monitor < 1.0.1