#VU121657 Path traversal in Soda PDF Desktop - CVE-2025-14413

 

#VU121657 Path traversal in Soda PDF Desktop - CVE-2025-14413

Published: January 19, 2026


Vulnerability identifier: #VU121657
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-14413
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Soda PDF Desktop
Software vendor:
Avanquest

Description

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can trick a victim to open a specially crafted CBZ file and upload arbitrary files on the system, leading to arbitrary code execution.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links