CVE-2025-5964: M-Files Server

Medium severity, CVSS 6.5. EPSS: 12.7% chance of exploitation in the next 30 days.

A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.

Affected products

  • M-Files M-Files Server: before 24.8.13981.16 (fixed in 24.8.13981.16); from 25.2.14524.3, before 25.2.14524.9 (fixed in 25.2.14524.9); from 25.3.14681.7, before 25.6.14925.0 (fixed in 25.6.14925.0)

Published 2025-06-15. Last modified 2026-06-17.