CVE-2025-57403: Abelche Cola Dnslog
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.
Affected products
- Abelche Cola Dnslog: version 1.3.2 only
Published 2025-12-26. Last modified 2026-10-05.