Impact
The vulnerability arises from a Path Traversal flaw (CWE-22) in the Oracle GraalVM compiler component, allowing an unauthenticated attacker who can reach the service over HTTP to gain full control of the GraalVM instance. This flaw can lead to the compromise of confidentiality, integrity, and availability, as reflected in the CVSS base score of 8.1.
Affected Systems
Oracle GraalVM for JDK 23.0.13.1 for Java 17, Oracle GraalVM for JDK 23.1.12.1 for Java 21, and the generic Oracle GraalVM 25.0.4.1 build are affected.
Risk and Exploitability
The EPSS score is less than 1 percent, indicating low current exploit activity, and the vulnerability is not listed in the CISA KEV catalog. Despite the low EPSS, the high CVSS score and the fact that no authentication or privilege is required mean that any host with network access to the GraalVM HTTP endpoint could exploit the flaw to achieve remote code execution.
OpenCVE Enrichment