CVE-2025-66480Disclosure(wildfirechat / im-server)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wildfirechat im-server systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an endpoint (/fs) that handles multipart file uploads but fails to properly sanitize the filename provided by the user. Specifically, the writeFileUploadData method directly concatenates the configured storage directory with the filename extracted from the upload request without stripping directory traversal sequences (e.g., ../../). This vulnerability allows an attacker to write arbitrary files to any location on the server's filesystem where the application process has write permissions. By uploading malicious files (such as scripts, executables, or overwriting configuration files like authorized_keys or cron jobs), an attacker can achieve Remote Code Execution (RCE) and completely compromise the server. This vulnerability is fixed in 1.4.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • im-server

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-02); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
im-server

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-02: 2Mentions · 2026-02-03: 2Mentions · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-02: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 102-0202-0302-04
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-02-032
Disclosure1Patch1
2026-02-041
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Wildfire IM Server is affected by a critical Arbitrary File Upload via Directory Traversal vulnerability (CVE-2025-66480). Update is advised for #infosec #cybersecurity professionals. More details: https://www.pulsepatch.io/posts/cve-2025-66480-wildfire-im-server-arbitrary-file-upload

    Post summary

    Wildfire IM Server has a critical CVE-2025-66480 that enables arbitrary file uploads through directory traversal; users are advised to update to mitigate the risk.

    0000041
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-66480 Directory Traversal in Wildfire IM Server Leading to Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-66480

    Post summary

    The post announces CVE-2025-66480 as a directory traversal vulnerability in Wildfire IM Server that can lead to remote code execution, with no further details on PoC, exploit tools, patches, or active exploitation.

    0000074
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-66480: CRITICAL] Critical vulnerability found in Wildfire IM's instant messaging server (prior to 1.4.3). Attackers can exploit the flaw to achieve Remote Code Execution. Update to version 1.4.3 fo...#cve,CVE-2025-66480,#cybersecurity https://cvefind.com/CVE-2025-66480

    Post summary

    A critical RCE vulnerability (CVE‑2025‑66480) exists in Wildfire IM’s instant messaging server before v1.4.3; users should update to version 1.4.3 to remediate.

    0000079
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-66480 Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file… https://www.cve.org/CVERecord?id=CVE-2025-66480

    Post summary

    The text announces a critical vulnerability in Wildfire IM's im‑server component (pre‑1.4.3) but provides no further technical or mitigation details.

    00000143
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-66480: Wildfire has Arbitrary File Uplo... Unsanitized path concatenation in Wildfire's UploadFileAction is trivial to weaponize - upload to ../../authorized_keys... https://zerodaysignal.com/vulnerability/CVE-2025-66480 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A CVE-2025-66480 vulnerability in Wildfire allows arbitrary file uploads via unsanitized path concatenation, with a link to a vulnerability page.

    0000049
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwildfirechatim-server---

Explore more