Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the review_paper function in backend/app.py. The vulnerability allows malicious users to access arbitrary PDF files on the server by providing crafted file paths that bypass the intended security restrictions. This vulnerability allows attackers to: read any PDF file accessible to the server process, potentially access sensitive documents outside the intended directory and perform reconnaissance on the server's file system structure. This issue does not currently have a fix.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tiny-scientist Project
Tiny-scientist Project tiny-scientist |
|
Vendors & Products |
Tiny-scientist Project
Tiny-scientist Project tiny-scientist |
Mon, 11 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and review. In versions 0.1.1 and below, a critical path traversal vulnerability has been identified in the review_paper function in backend/app.py. The vulnerability allows malicious users to access arbitrary PDF files on the server by providing crafted file paths that bypass the intended security restrictions. This vulnerability allows attackers to: read any PDF file accessible to the server process, potentially access sensitive documents outside the intended directory and perform reconnaissance on the server's file system structure. This issue does not currently have a fix. | |
Title | Path Traversal Vulnerability in PDF Review Function (CWE-22) | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-09T02:02:30.630Z
Updated: 2025-08-11T14:03:29.406Z
Reserved: 2025-08-07T18:27:23.304Z
Link: CVE-2025-55149

Updated: 2025-08-11T14:01:57.523Z

Status : Awaiting Analysis
Published: 2025-08-09T03:15:47.770
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-55149

No data.