Path Traversal Vulnerability in Assemblyline 4 Service Client by Cybercentre Canada
CVE-2025-55013

4.2MEDIUM

Key Information:

Vendor
CVE Published:
9 August 2025

What is CVE-2025-55013?

The Assemblyline 4 Service Client has a vulnerability that allows a malicious server to exploit the API by returning a crafted SHA-256 value, which can lead to a path traversal attack. This vulnerability permits a compromised server or a man-in-the-middle (MITM) to manipulate the local file name, forcing the client to write data to an arbitrary location on the disk, potentially compromising system integrity. The issue has been addressed in version 4.6.1.dev138.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

assemblyline < 4.6.1.dev138

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.