cbcvebase.
CVE-2025-7626
published 2025-07-14

CVE-2025-7626: A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this…

PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.53%
40.7th percentile
A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

Affected

10 ranges
VendorProductVersion rangeFixed in
gitgit>= 0 < 1:2.34.1-1ubuntu1.141:2.34.1-1ubuntu1.14
gitgit>= 0 < 1:2.34.1-1ubuntu1.151:2.34.1-1ubuntu1.15
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm101:2.7.4-0ubuntu1.10+esm10
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm111:2.7.4-0ubuntu1.10+esm11
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm31:2.17.1-1ubuntu0.18+esm3
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm41:2.17.1-1ubuntu0.18+esm4
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm21:2.25.1-1ubuntu3.14+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm31:2.25.1-1ubuntu3.14+esm3
yijiusmilekkfileviewofficeedit<= 2019-03-19
yijiusmilekkfileviewofficeedit

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.