THREAT OPS › Threat News › [GHSA] GHSA-c23q-fw86-9h5x (medium) — LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
[GHSA] GHSA-c23q-fw86-9h5x (medium) — LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
GHSA-c23q-fw86-9h5x Severity: medium CVE: CVE-2025-58363
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
### Summary A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system.
### Details I
MITRE ATT&CK techniques
- File DeletionT1070.004
Indicators of compromise
- CVE-2025-58363cve
Original source: https://github.com/advisories/GHSA-c23q-fw86-9h5x