Vulnerability Intelligence Report
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVE-2025-54261
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Temporal Score:10.0
EPSS Probability:19.93%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Adobe | ColdFusion | 0 <= 2021.21 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
19.934%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2025-07-17T21:15:02 |
| Published | 2025-09-09T16:58:42 |
| Patch Date | 2025-09-09 |
| Last Updated | 2025-10-08T15:55:34 |
Community Chatter & Buzz