CVE-2025-56869: Sync-In Server
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.
Affected products
- Sync-In Sync-In Server: up to and including 1.1.1
Published 2025-09-19. Last modified 2026-06-17.