Authenticated Path Traversal Vulnerability in RomM Self-Hosted ROM Manager
CVE-2025-53908

8.3HIGH

Key Information:

Vendor

Rommapp

Status
Vendor
CVE Published:
16 July 2025

What is CVE-2025-53908?

RomM, a self-hosted ROM manager, contains an authenticated path traversal vulnerability in its '/api/raw' endpoint. Users operating versions older than 3.10.3 and 4.0.0-beta.3 may expose sensitive information, such as passwords and user data, to unauthorized individuals. This flaw affects even non-privileged users, highlighting serious security risks in multi-user environments. Updating to the latest versions is crucial to mitigate this vulnerability and protect sensitive data.

Affected Version(s)

romm < 3.10.3 < 3.10.3

romm < 4.0.0-beta.3 < 4.0.0-beta.3

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53908 : Authenticated Path Traversal Vulnerability in RomM Self-Hosted ROM Manager