CVE-2025-67487 - CVE House
Back to Database
Status published Medium CVE-2025-67487

Static Web Server is vulnerable to symbolic link Path Traversal

Vulnerability Description

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root folder. SWS generally does not prevent symlinks from escaping the web server’s root directory. Therefore, if a malicious actor gains access to the web server’s root directory, they could create symlinks to access other files outside the designated web root folder either by URL or via the directory listing. This issue is fixed in version 2.40.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-67487

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

static-web-server

View all reports →

Affected Software

static-web-server
Vulnerable Versions:
< 2.40.1

Timeline

Official Publish: December 9th, 2025
Last Modified: December 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.