Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted.
ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 02 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution. | |
| Title | GrapesJsBuilder File Upload allows all file uploads | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Mautic
Published:
Updated: 2025-12-02T17:10:25.179Z
Reserved: 2025-12-01T15:20:24.945Z
Link: CVE-2025-13827
Updated: 2025-12-02T17:10:19.200Z
Status : Awaiting Analysis
Published: 2025-12-02T17:16:03.847
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13827
No data.
OpenCVE Enrichment
No data.