{"id":"CVE-2025-58432","summary":"ZimaOS  Privilege Escalation using localhost calls to File API Upload","details":"ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/files/file/uploadV2 endpoint allows file upload from ANY USER who has access to localhost. File uploads are performed AS ROOT.","aliases":["GHSA-3gp9-43rg-xrcc"],"modified":"2026-03-14T12:45:18.182266Z","published":"2025-09-17T17:31:20.968Z","database_specific":{"cwe_ids":["CWE-250","CWE-269"],"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58432.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58432.json"},{"type":"ADVISORY","url":"https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-3gp9-43rg-xrcc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58432"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/icewhaletech/zimaos","events":[{"introduced":"0"},{"last_affected":"091b5355a157924b14a733c1f0e520f2f8627fd6"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"1.4.1"}]}}],"versions":["0.4.8","0.4.8.1","0.4.9","0.4.9.1","0.4.9.2","0.4.9.3","0.4.9.4","0.5.0","1.0.0","1.1.0","1.2.2","1.2.3","1.2.3-beta1","1.2.4","1.2.4-beta1","1.2.4-beta2","1.2.5","1.2.5-beta1","1.2.5-beta2","1.2.5-beta3","1.3.0","1.3.0-1","1.3.0-2","1.3.0-beta1","1.3.1","1.3.1-1","1.3.1-beta1","1.3.2","1.3.2-1","1.3.2-beta1","1.3.2-beta2","1.3.3","1.3.3-beta1","1.4.0","1.4.0-beta1","1.4.0-beta2","1.4.1","1.4.1-beta1","1.4.1-beta2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58432.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}