Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions 0.16.11 and 0.17.2.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions 0.16.11 and 0.17.2.
Title CFiles Unauthorized Folder/ZIP Access in Public Spaces
Weaknesses CWE-284
CWE-285
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-25T23:38:49.198Z

Reserved: 2025-11-18T16:14:56.694Z

Link: CVE-2025-65963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-26T00:15:51.100

Modified: 2025-11-26T00:15:51.100

Link: CVE-2025-65963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.