CVE-2025-54387 - CVE House
Back to Database
Status published Medium CVE-2025-54387

IPX is Vulnerable to Path Traversal via Prefix Matching Bypass

Vulnerability Description

IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 through 3.1.0, the approach used to check whether a path is within allowed directories is vulnerable to path prefix bypass when the allowed directories do not end with a path separator. This occurs because the check relies on a raw string prefix comparison. This is fixed in versions 1.3.2, 2.1.1 and 3.1.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54387

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ipx
Vulnerable Versions:
< 1.3.2, >= 2.0.0-0, < 2.1.1, >= 3.0.0, < 3.1.1

Timeline

Official Publish: August 5th, 2025
Last Modified: August 5th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)