CVE-2025-24786General(clidey / whodb)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sqlite3 database present on the host machine that the application is running on. Affected versions of WhoDB allow users to connect to Sqlite3 databases. By default, the databases must be present in `/db/` (or alternatively `./tmp/` if development mode is enabled). If no databases are present in the default directory, the UI indicates that the user is unable to open any databases. The database file is an user-controlled value. This value is used in `.Join()` with the default directory, in order to get the full path of the database file to open. No checks are performed whether the database file that is eventually opened actually resides in the default directory `/db`. This allows an attacker to use path traversal (`../../`) in order to open any Sqlite3 database present on the system. This issue has been addressed in version 0.45.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-35

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • whodb

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-01); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
whodb

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-01: 1Mentions · 2026-02-03: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-03: 102-0102-03
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-011
General1
2026-02-031
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-24786 - high 🚨 WhoDB < 0.45.0 - Path Traversal > WhoDB contains a path traversal caused by lack of validation when opening database fi... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-24786 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2025-24786 is a path traversal vulnerability in WhoDB versions below 0.45.0 caused by missing validation when opening database files.

    00011175
    890 followersView on X
  • Basic_Beny@basic_beny
    General

    ``` Just submitted my first PR to nuclei-templates — wrote a detection for CVE-2025-24786, a path traversal in WhoDB that lets you read any sqlite db on the box without auth. small contribution but feels good to give back to tools i actually use. https://github.com/projectdiscovery/nuclei-templates/pull/15114 ```

    Post summary

    The user added a detection template for CVE-2025-24786, a WhoDB path traversal that permits unauthenticated reading of SQLite databases. No exploit, patch, or active exploitation is reported.

    0000067
    496 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appclideywhodb---

Explore more