CVE-2025-13265: Lsfusion Platform
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traversal. It is possible to initiate the attack remotely.
Affected products
- Lsfusion Lsfusion Platform: up to and including 6.1
Published 2025-11-17. Last modified 2026-10-07.