Description
Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has been patched in version 6.6.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18624 | Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has been patched in version 6.6.10. |
References
History
Wed, 18 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Jun 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has been patched in version 6.6.10. | |
| Title | Lychee Path Traversal Vulnerability | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-18T14:00:25.727Z
Reserved: 2025-06-13T19:17:51.729Z
Link: CVE-2025-50202
Updated: 2025-06-18T13:59:34.487Z
Status : Deferred
Published: 2025-06-18T05:15:49.900
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-50202
No data.
OpenCVE Enrichment
Updated: 2025-06-20T13:55:53Z
Weaknesses
EUVD