File Access Vulnerability in ZimaOS Affecting Localhost Users
CVE-2025-58431
4.8MEDIUM
What is CVE-2025-58431?
ZimaOS, derived from CasaOS, contains a serious flaw in its file download mechanism. In version 1.4.1 and earlier, the /v2_1/files/file/download endpoint allows any user with access to the localhost to read files. This vulnerability occurs because file reads are executed with root privileges, which can lead to unauthorized access to sensitive data. Users and administrators must take immediate action to secure their systems.
Affected Version(s)
ZimaOS <= 1.4.1