
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55988 is a path traversal vulnerability in DreamFactory Core affecting the /Controllers/RestController.php component. It allows authenticated attackers with high privileges to traverse directories via an unsanitized URI path, potentially enabling remote code execution. The vulnerability affects DreamFactory Core versions prior to 1.0.4 (specifically confirmed in v1.0.3). It was published on March 20, 2026, with a patch released the same day. The CVSS v3.1 base score is 7.2 (High) (GitHub Advisory).
The root cause is improper input sanitization (CWE-22) in the handleServiceRequest() method of src/Http/Controllers/RestController.php. The $resource variable, derived from the URI path, was passed without stripping .. sequences, allowing attackers to craft requests with path traversal payloads (e.g., ../../sensitive/file) to access files outside the intended directory. The fix, introduced in commit 5435460, adds a single line: $resource = str_replace(['..'], '', $resource); to remove double-dot sequences before further processing. Exploitation requires network access and high-privilege credentials, but no user interaction is needed (GitHub Commit, GitHub Advisory). A technical write-up is referenced at https://pentest-tools.com/PTT-2025-001-RemoteCodeExecution-via-URL-Path-Traversal.pdf.
Successful exploitation allows a privileged attacker to read, modify, or delete arbitrary files on the server hosting DreamFactory Core, with high confidentiality, integrity, and availability impacts. This could expose sensitive configuration files, credentials, or application data, and may facilitate remote code execution as described in the referenced pentest advisory. The attack is network-based and requires no user interaction, making it particularly dangerous in environments where DreamFactory is exposed to untrusted networks (GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Feedly). The EPSS score is approximately 0.14% (34th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege credentials, which limits the attacker pool but does not eliminate risk in environments with weak credential hygiene.
.. sequences targeting the REST API endpoint, e.g., GET /api/v2/../../etc/passwd or similar path traversal strings routed through RestController.php.$resource variable will resolve the traversal path outside the intended directory... or URL-encoded traversal sequences (e.g., %2e%2e, %2F..) in the URI path./api/v2/ or similar endpoints with path components containing double-dot sequences; HTTP 200 responses to requests with traversal patterns./etc/passwd, .env, database configuration files) by the web server process user.bash, curl, wget).Upgrade DreamFactory Core to version 1.0.4 or later, which strips .. sequences from the $resource URI parameter in RestController.php (GitHub Advisory, GitHub Commit). As a temporary workaround, implement network-level controls (WAF rules or reverse proxy filters) to block requests containing .. or URL-encoded traversal sequences in URI paths. Restrict access to the DreamFactory admin and API interfaces to trusted IP ranges and enforce strong credential policies for privileged accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."