Path Traversal Vulnerability in Assemblyline 4 Service Client by Cybercentre Canada
CVE-2025-55013

10CRITICAL

Key Information:

Vendor
CVE Published:
9 August 2025

What is CVE-2025-55013?

The Assemblyline 4 Service Client has a vulnerability that allows a malicious server to exploit the API by returning a crafted SHA-256 value, which can lead to a path traversal attack. This vulnerability permits a compromised server or a man-in-the-middle (MITM) to manipulate the local file name, forcing the client to write data to an arbitrary location on the disk, potentially compromising system integrity. The issue has been addressed in version 4.6.1.dev138.

Affected Version(s)

assemblyline < 4.6.1.dev138

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55013 : Path Traversal Vulnerability in Assemblyline 4 Service Client by Cybercentre Canada