ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier...
Critical severity
Unreviewed
Published
Sep 9, 2025
to the GitHub Advisory Database
•
Updated Sep 9, 2025
Description
Published by the National Vulnerability Database
Sep 9, 2025
Published to the GitHub Advisory Database
Sep 9, 2025
Last updated
Sep 9, 2025
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. Scope is changed.
References