CVE-2025-30224
Linux Debian vulnerability analysis and mitigation

Overview

MyDumper, a MySQL Logical Backup Tool, was found to contain a security vulnerability identified as CVE-2025-30224. The vulnerability was discovered and disclosed on April 1, 2025. The issue affects versions prior to 0.18.2-8, where the MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems when connecting to untrusted MySQL servers (GitHub Advisory, NVD).

Technical details

The vulnerability stems from the MySQL C client library's LOAD LOCAL INFILE query functionality. MyDumper has this local infile option enabled by default and lacks an option to disable it. When a client connects to an untrusted MySQL server, the server can craft specific responses that trigger arbitrary file reads on the client system. The vulnerability has been assigned a CVSS v4.0 score of 5.1 (MEDIUM) with the vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N (GitHub Advisory).

Impact

The vulnerability allows authenticated remote actors to read arbitrary files from client systems, potentially leading to sensitive information disclosure. This can occur when clients connect to untrusted MySQL servers without explicitly disabling the local infile capability (GitHub Advisory).

Exploitability

A proof-of-concept exploit has been documented that demonstrates the vulnerability. The attack can be executed by setting up a malicious MySQL 5.7 server with specific configurations and utilizing the Rewriter Query Rewrite Plugin to trigger arbitrary file reads from the client system (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 0.18.2-8 of MyDumper. The fix introduces a new command --local-infile option, similar to the one that exists for the MySQL client, allowing users to control this functionality (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48120HIGH8.6
  • Linux Debian logoLinux Debian
  • kakoune
NoNoAug 07, 2026
CVE-2026-42170HIGH7.8
  • Linux Debian logoLinux Debian
  • gimp-help-browser
NoYesAug 08, 2026
CVE-2026-71870MEDIUM4.8
  • Python logoPython
  • pypdf2
NoYesAug 07, 2026
CVE-2026-68082NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026
CVE-2026-68081NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management