CVE-2025-70849Disclosure(stefanprodan / podinfo)

LOWCVSS 6.1 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • podinfo

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
podinfo

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-03: 2PoC Mentioned / Linked · 2026-02-03: 1Technical Details · 2026-02-03: 102-03
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-70849 Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The applicatio… https://www.cve.org/CVERecord?id=CVE-2025-70849

    Post summary

    The text announces CVE-2025-70849 as an unauthenticated arbitrary file upload vulnerability in podinfo up to 6.9.0, enabling file uploads via a crafted POST to the /store endpoint, without mention of PoC, exploit code, patch, or active exploitation.

    00010220
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    PoC

    CVE-2025-70849 PoC and Advisory for CVE-2025-70849 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70849

    Post summary

    The post announces a proof‑of‑concept and advisory for CVE-2025-70849, linking to a vulnerability details page, but does not provide exploitation details or mitigation information.

    00000107
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstefanprodanpodinfo-kubernetes-

Explore more