RomM vulnerable to Authenticated Path Traversal
Vulnerability Description
RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone running the latest version of RomM and has multiple users, even unprivileged users, such as the kiosk user in the official implementation, may be affected. This allows the leakage of passwords and users that may be stored on the system. Versions 3.10.3 and 4.0.0-beta.3 contain a patch.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53908
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/rommapp/romm/security/advisories/GHSA-fx9g-xw4j-jwc3
- https://github.com/rommapp/romm/commit/7c94cb05e74ddb6a6af7b82320686c01754e9966
- https://github.com/rommapp/romm/commit/baa1a9759079c36e36a9f10c920c46b57d0b6151
- https://github.com/rommapp/romm/blob/4.0.0-beta.2/backend/endpoints/raw.py#L31
More from rommapp
View All →Affected Vendor
rommapp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.