Impact
DeepTutor 1.4.0 contains a path traversal flaw in the EditFileTool.execute method. An attacker who can reach the live tutorbot WebSocket interface can direct the tool layer to write or edit files using any absolute path on the host system. Consequently, the attacker can modify configuration files, overwrite critical data, or place malicious code that may be executed by the process running the bot service, leading to full remote code execution. The vulnerability therefore exposes both confidentiality and integrity, with the potential for a total loss of control over the affected host.
Affected Systems
The flaw affects DeepTutor version 1.4.0. No specific vendor is listed, but the product is the DeepTutor WebSocket tutoring platform, which must be running that version to be vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the security agency’s KEV catalog, so the exact prevalence of exploitation is unknown. However, the flaw permits remote exploitation via a standard WebSocket connection, which is a common remote interface. The lack of restrictions on the EditFileTool implies that any authenticated or unauthenticated user who can reach the WebSocket endpoint can trigger the file write operation. Given the potential to overwrite arbitrary files, the risk is high, especially if the DeepTutor service runs with elevated privileges.
OpenCVE Enrichment