Intel

AIKIDO-2025-10625

Akavache is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 10, 2025

70

High Risk

This Affects:

dotnetAkavache
11.0.1 - 11.3.2
Fixed in 11.3.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Path Traversal due to improper neutralization of user-controlled input used in filesystem path construction. An attacker could supply a malicious filename containing traversal sequences (e.g., ../../../etc/passwd) to escape the intended directory and access, overwrite, or create arbitrary files on the server filesystem, potentially leading to unauthorized information disclosure or system compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Akavache is vulnerable to Path Traversal in versions 11.0.1 - 11.3.2.

How to fix this

Upgrade the Akavache library to the patch version.