CVE-2025-55988: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-55988 is a path traversal vulnerability in DreamFactory Core affecting the /Controllers/RestController.php component. It allows authenticated attackers with high privileges to traverse directories via an unsanitized URI path, potentially enabling remote code execution. The vulnerability affects DreamFactory Core versions prior to 1.0.4 (specifically confirmed in v1.0.3). It was published on March 20, 2026, with a patch released the same day. The CVSS v3.1 base score is 7.2 (High) (GitHub Advisory).

Technical details

The root cause is improper input sanitization (CWE-22) in the handleServiceRequest() method of src/Http/Controllers/RestController.php. The $resource variable, derived from the URI path, was passed without stripping .. sequences, allowing attackers to craft requests with path traversal payloads (e.g., ../../sensitive/file) to access files outside the intended directory. The fix, introduced in commit 5435460, adds a single line: $resource = str_replace(['..'], '', $resource); to remove double-dot sequences before further processing. Exploitation requires network access and high-privilege credentials, but no user interaction is needed (GitHub Commit, GitHub Advisory). A technical write-up is referenced at https://pentest-tools.com/PTT-2025-001-RemoteCodeExecution-via-URL-Path-Traversal.pdf.

Impact

Successful exploitation allows a privileged attacker to read, modify, or delete arbitrary files on the server hosting DreamFactory Core, with high confidentiality, integrity, and availability impacts. This could expose sensitive configuration files, credentials, or application data, and may facilitate remote code execution as described in the referenced pentest advisory. The attack is network-based and requires no user interaction, making it particularly dangerous in environments where DreamFactory is exposed to untrusted networks (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Feedly). The EPSS score is approximately 0.14% (34th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege credentials, which limits the attacker pool but does not eliminate risk in environments with weak credential hygiene.

Exploitation steps

  1. Reconnaissance: Identify DreamFactory Core instances running version 1.0.3 or earlier, accessible over the network. Check version information via the DreamFactory admin panel or API endpoints.
  2. Authentication: Obtain or use existing high-privilege credentials (e.g., admin account) to authenticate to the DreamFactory API.
  3. Craft traversal payload: Construct a malicious URI containing .. sequences targeting the REST API endpoint, e.g., GET /api/v2/../../etc/passwd or similar path traversal strings routed through RestController.php.
  4. Send request: Submit the crafted HTTP request to the vulnerable endpoint. The unsanitized $resource variable will resolve the traversal path outside the intended directory.
  5. Access arbitrary files: Retrieve sensitive files (e.g., configuration files, credentials, application secrets) or, per the referenced advisory, potentially achieve remote code execution by targeting writable paths or script files (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Network: Unusual HTTP requests to DreamFactory API endpoints containing .. or URL-encoded traversal sequences (e.g., %2e%2e, %2F..) in the URI path.
  • Logs: Web server or application access logs showing requests to /api/v2/ or similar endpoints with path components containing double-dot sequences; HTTP 200 responses to requests with traversal patterns.
  • File System: Unexpected access to sensitive files (e.g., /etc/passwd, .env, database configuration files) by the web server process user.
  • Process: Unusual child processes spawned by the PHP/web server process if remote code execution is achieved (e.g., bash, curl, wget).

Mitigation and workarounds

Upgrade DreamFactory Core to version 1.0.4 or later, which strips .. sequences from the $resource URI parameter in RestController.php (GitHub Advisory, GitHub Commit). As a temporary workaround, implement network-level controls (WAF rules or reverse proxy filters) to block requests containing .. or URL-encoded traversal sequences in URI paths. Restrict access to the DreamFactory admin and API interfaces to trusted IP ranges and enforce strong credential policies for privileged accounts.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management