CVE-2025-2070: Filez Client

Medium severity, CVSS 5.0. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.

Affected products

  • Filez Client: before 11.0.0.10 (fixed in 11.0.0.10)

Published 2025-04-25. Last modified 2026-06-17.