Security Advisory

CVE-2025-60915Authenticated local file inclusion (LFI) and configuration file exposure

OpenAtlas · Austrian Academy of Sciences (ÖAW)

CVE published 24 Nov 2025 · discovered 8 Aug 2025

Overview

In OpenAtlas, the size parameter influenced the directory path used by a file endpoint. A low-privileged user could escape the intended directory and access files outside the uploads area.

Technical findings

At /display/<filename>, the size parameter selected a subdirectory. The value was not restricted to valid sizes or directory names and was incorporated directly into the constructed filesystem path.

An authenticated user could therefore redirect the target path outside the intended directory. Technically, this constitutes a path traversal / local file inclusion issue.

Configuration files make this especially serious: database credentials, Flask secrets or similar keys can enable subsequent attacks far beyond the initial file read.

Why it matters

Exploitation requires a valid low-privileged session. What matters next is which files the application process can read. Configuration files and secrets can quickly turn file disclosure into a much larger compromise.

Potential impact

  • Authenticated users with minimal privileges may read files outside the intended directory, including configuration files and secrets.

Remediation

  • Upgrade to OpenAtlas 8.13.0 or later.
  • Validate the size parameter against a strict allowlist of expected values.
  • Canonicalize resolved file paths and ensure the result remains inside the intended base directory.
  • Avoid storing secrets unnecessarily within application paths and apply least-privilege filesystem permissions.

Affected and fixed versions

Affected<= 8.12.0
Fixed / vendor-confirmed8.13.0

Disclosure timeline

  1. Discovery

    Identified during an on-premises penetration test.

  2. Report submitted

    Sent technical details and reproduction steps to the vendor.

  3. Fix confirmed

    OpenAtlas confirmed that the finding had been addressed.

  4. CVE assignment

    Received the CVE ID during coordinated disclosure.

References

Related OpenAtlas research