Vulnerability Description
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Coldfusion | 2021 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-54261?
CVE-2025-54261 is a vulnerability with a CVSS score of 10.0 (CRITICAL). ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary co...
How severe is CVE-2025-54261?
CVE-2025-54261 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-54261?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Coldfusion.