DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulnerability.
The specific flaw exists within the implementation of the saveZipFile method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26589.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dreamfactory
Dreamfactory dreamfactory |
|
| Vendors & Products |
Dreamfactory
Dreamfactory dreamfactory |
Tue, 23 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementation of the saveZipFile method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26589. | |
| Title | DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published: 2025-12-23T21:42:47.128Z
Updated: 2025-12-24T15:50:50.852Z
Reserved: 2025-11-25T21:40:28.547Z
Link: CVE-2025-13700
Updated: 2025-12-24T15:50:47.103Z
Status : Received
Published: 2025-12-23T22:15:44.927
Modified: 2025-12-23T22:15:44.927
Link: CVE-2025-13700
No data.