CVE-2025-24961
S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backends
EPSS 0.35%
Description
### Impact Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to authenticated clients. ### Patches Upgrade to S3Proxy 2.6.0 which includes apache/jclouds@b0819e0ef5e08c792a4d1724b938714ce9503aa3 and 86b6ee4749aa163a78e7898efc063617ed171980. ### Workarounds None ### References Privately reported by XBOW Team @xbow-security.
How to fix CVE-2025-24961
To remediate CVE-2025-24961, upgrade the affected package to a fixed version below.
- Maven/org.gaul:s3proxy—upgrade to 2.6.0 or later
Is CVE-2025-24961 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.6.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |