Vulnerability Description
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartbear | Swagger Petstore | 1.0.7 |
Related Weaknesses (CWE)
References
- https://gist.github.com/HouqiyuA/3c36f78e8de9f6a3cfb0959477c07443ExploitThird Party Advisory
- https://github.com/swagger-api/swagger-petstoreProduct
- https://petstore3.swagger.io/#/pet/updatePetProduct
FAQ
What is CVE-2025-29157?
CVE-2025-29157 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including...
How severe is CVE-2025-29157?
CVE-2025-29157 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-29157?
Check the references section above for vendor advisories and patch information. Affected products include: Smartbear Swagger Petstore.