CVE-2025-29865 - CVE House
Back to Database
Status published High CVE-2025-29865

: Improper Limitation of a Pathname to a Restricted Directory...

Vulnerability Description

: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29865

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

X-Free Uploader
Vulnerable Versions:
1.0.1.0084, 2.0.1.0034

Timeline

Official Publish: August 7th, 2025
Last Modified: August 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)