Path Traversal Vulnerability in Assemblyline 4 Service Client by Cybercentre Canada
CVE-2025-55013
10CRITICAL
What is CVE-2025-55013?
The Assemblyline 4 Service Client has a vulnerability that allows a malicious server to exploit the API by returning a crafted SHA-256 value, which can lead to a path traversal attack. This vulnerability permits a compromised server or a man-in-the-middle (MITM) to manipulate the local file name, forcing the client to write data to an arbitrary location on the disk, potentially compromising system integrity. The issue has been addressed in version 4.6.1.dev138.
Affected Version(s)
assemblyline < 4.6.1.dev138