CVE-2026-25099
Remote Code Execution via Unrestricted File Upload in Bludit
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
| CWE | CWE-434 |
| Vendor | bludit |
| Product | bludit |
| Published | Mar 27, 2026 |
| Last Updated | Mar 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for bludit bludit
Be the first to know when new unknown vulnerabilities affecting bludit bludit are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Bludit / Bludit
0 < 3.18.4
References
Credits
Arkadiusz Marta