๐Ÿ” CVE Alert

CVE-2025-34171

UNKNOWN 0.0

CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a user-controlled path parameter to access files under /var/lib/casaos/1/, which reveals installed applications and configuration details. Additionally, /v1/sys/debug discloses host operating system, kernel, hardware, and storage information. The endpoints also return distinct error messages, enabling file existence enumeration of arbitrary paths on the underlying host filesystem. This information disclosure can be used for reconnaissance and to facilitate targeted follow-up attacks against services deployed on the host.

CWE CWE-862 CWE-497
Vendor icewhale tech
Product casaos
Published Jan 3, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for icewhale tech casaos

Be the first to know when new unknown vulnerabilities affecting icewhale tech casaos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

IceWhale Tech / CasaOS
0 โ‰ค 0.4.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
casaos.zimaspace.com: https://casaos.zimaspace.com/ github.com: https://github.com/IceWhaleTech/CasaOS vulncheck.com: https://www.vulncheck.com/advisories/casaos-unauthenticated-file-and-debug-data-exposure

Credits

Mike G.A (Eyodav) VulnCheck