F
ile upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
References
| Link | Resource |
|---|---|
| https://www.agora-project.net | Product |
| https://www.helx.io/blog/advisory-agora-project/ | Third Party Advisory |
Configurations
History
21 Jan 2026, 14:42
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Agora-project
Agora-project agora-project |
|
| References | () https://www.agora-project.net - Product | |
| References | () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory | |
| CPE | cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:* |
15 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-15 16:16
Updated : 2026-01-21 14:42
NVD link : CVE-2025-67079
Mitre link : CVE-2025-67079
CVE.ORG link : CVE-2025-67079
JSON object : View
Products Affected
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type