CVE-2022-25297
NixOS vulnerability analysis and mitigation

Overview

The vulnerability CVE-2022-25297 affects the drogonframework/drogon package versions before 1.7.5. This security flaw involves unsafe handling of file names during upload using the HttpFile::save() method, which could enable attackers to write files to arbitrary locations outside the designated target folder. The vulnerability was disclosed on February 21, 2022 (NVD, Snyk).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 8.8 (High severity) with the following metrics: Attack Vector: Network, Attack Complexity: Low, Privileges Required: Low, User Interaction: None, Scope: Unchanged, and Impact scores of High for Confidentiality, Integrity, and Availability. The issue stems from improper validation of file paths during file uploads, which could allow an attacker to manipulate the file path and write files outside the intended upload directory (Snyk).

Impact

The vulnerability can lead to arbitrary file writes outside the designated upload folder, potentially allowing attackers to write files anywhere on the system. This could result in system compromise through overwriting critical files or inserting malicious content. The high CVSS impact scores for confidentiality, integrity, and availability indicate severe potential consequences if exploited (Snyk).

Mitigation and workarounds

The recommended mitigation is to upgrade drogonframework/drogon to version 1.7.5 or higher, which contains the fix for this vulnerability. The fix implements proper path validation to prevent directory traversal attempts (GitHub PR, Snyk).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management