CISA Thorium insecure downloaded file path validation
Vulnerability Description
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35430
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- , OpenAI Security Research
References
More from CISA
View All →Affected Vendor
CISA
View all reports →