CVE-2025-57403: Abelche Cola Dnslog

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.

Affected products

  • Abelche Cola Dnslog: version 1.3.2 only

Published 2025-12-26. Last modified 2026-10-05.