Intel

AIKIDO-2025-10545

cloudinary is vulnerable to Improper Neutralization of Parameter/Argument Delimiters

Improper Neutralization of Parameter/Argument DelimitersCVE-2025-12613 Published Aug 12, 2025

85

High Risk

This Affects:

JScloudinary
1.0.0 - 2.6.1
Fixed in 2.7.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to parameter injection in the api_sign_request function. The flaw occurs because ampersands (&) in parameter values are not properly handled, allowing attackers to inject additional parameters and potentially alter request behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cloudinary is vulnerable to Improper Neutralization of Parameter/Argument Delimiters in versions 1.0.0 - 2.6.1.

How to fix this

Upgrade the cloudinary library to a patch version.