Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from improper directory access management. This vulnerability was remediated in version 7.5.021 of the product.
History

Fri, 26 Sep 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Rapid7
Rapid7 appspider Pro
Vendors & Products Rapid7
Rapid7 appspider Pro

Thu, 25 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
Description Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from improper directory access management. This vulnerability was remediated in version 7.5.021 of the product.
Title Rapid7 Appspider Broken Access Control Vulnerability
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2025-09-25T14:41:35.939Z

Updated: 2025-09-25T16:03:45.231Z

Reserved: 2025-04-16T00:09:11.312Z

Link: CVE-2025-36857

cve-icon Vulnrichment

Updated: 2025-09-25T16:03:30.714Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-25T15:16:11.060

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-36857

cve-icon Redhat

No data.