A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j8r2-47rx-qhw4 Robocode vulnerable to Directory Traversal in recursivelyDelete Method
Fixes

Solution

Fixed in commit 836c846 on 13/05/2025


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Robocode Project
Robocode Project robocode
Vendors & Products Robocode Project
Robocode Project robocode

Tue, 09 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 07:30:00 +0000

Type Values Removed Values Added
Description A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/
Title Directory Traversal in Robocode's CacheCleaner Component
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GovTech CSG

Published:

Updated: 2025-12-09T14:52:09.816Z

Reserved: 2025-12-09T07:11:42.252Z

Link: CVE-2025-14306

cve-icon Vulnrichment

Updated: 2025-12-09T14:52:07.667Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:38.477

Modified: 2025-12-09T18:37:13.640

Link: CVE-2025-14306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-10T17:52:32Z

Weaknesses