# CVE-2025-53513

## Summary

- **CVE ID:** CVE-2025-53513
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-24
- **Published:** Jul 8, 2025
- **Last Modified:** Mar 13, 2026

## Description

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

## Affected Products

- Canonical — Juju (2.0.0)
- Canonical — Juju (3.0.0)

## References

- [CNA](https://github.com/juju/juju/security/advisories/GHSA-24ch-w38v-xmh8)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.66%
- **EPSS Percentile:** 49.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._