CVE-2025-12613
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior. **Note:** Following our established security policy, we attempted to contact the maintainer regarding this vulnerability, but haven't received a response.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-88
- Published
- 2025-11-10
- Last modified
- 2026-08-15
Affected products
- n/a cloudinary
Weakness type
Related vulnerabilities
- CVE-2026-24061 — telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
- CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
- CVE-2026-27613 — CGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)
- CVE-2024-47516 — Pagure: argument injection in pagurerepo.log()
- CVE-2026-27947 — Group-Office Vulnerable to Remote Code Execution (RCE)
- CVE-2026-25134 — Group-Office Argument Injection in MaintenanceController::actionZipLanguage
- CVE-2025-49008 — Atheos Improper Input Validation Vulnerability Enables RCE in Common.php
- CVE-2026-27208 — api-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root Execution