CVE-2025-31131 is a path traversal vulnerability in YesWiki, a PHP-based wiki system. The vulnerable component is the squelette parameter, which can be manipulated to traverse directories and read files outside the intended application path. By supplying crafted path sequences, an attacker can cause the application to access arbitrary files on the server filesystem. The available information indicates the issue results in unauthorized file read access. The vulnerability is fixed in YesWiki version 4.5.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
squelette parameter where feasible. Apply strict server-side validation to limit the parameter to an allowlist of expected template names and reject path traversal sequences such as ../ and equivalent encoded forms. Reduce filesystem exposure by ensuring the web server/PHP process has least-privilege read permissions and by moving sensitive files outside locations readable by the application. Web application firewall rules may help detect and block traversal payloads, but should not be relied on as a complete fix.Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (`CVE-2025-31131.py`) and a README. The script targets CVE-2025-31131 in YesWiki (< 4.5.2), exploiting an unauthenticated path traversal via the `squelette` query parameter on the `/?UrkCEO/edit` route (with `theme=margot` and `style=margot.css`). Core capabilities: - Remote arbitrary file read over HTTP(S) by requesting `squelette=../.../<file>` (URL-encoded via `urllib.parse.quote`). - Defaults to reading `/etc/passwd`, but allows operator-specified file paths via `-f/--file`. - Single-target mode (`-u/--url`) and bulk scanning mode (`-l/--list`) with configurable threading (`--threads`, default 10) using `ThreadPoolExecutor`. - Basic success detection by searching response text for markers like `root:x:0:0:` or `bin/bash`; prints extracted snippet starting at `root:x:0:0:`. Notable implementation details: - Disables TLS certificate verification (`verify=False`) and suppresses urllib3 SSL warnings. - No post-exploitation beyond file disclosure; no write/RCE functionality present. Repository purpose: provide an operational PoC-style exploit/scanner to identify vulnerable YesWiki instances and retrieve arbitrary file contents via the vulnerable `squelette` parameter.
This repository contains a Python proof-of-concept exploit for CVE-2025-31131, a path traversal vulnerability in YesWiki versions prior to 4.5.2. The exploit allows unauthenticated attackers to read arbitrary files from the server by abusing the 'squelette' parameter in a crafted HTTP GET request. The main script, 'CVE-2025-31131.py', supports both single-target and bulk scanning modes, with multithreading for efficiency. The default file targeted is '/etc/passwd', but any file path can be specified. The README provides background on the vulnerability, usage instructions, and a sample manual exploitation request. No payloads for code execution or privilege escalation are included; the exploit is limited to file read operations. The repository is structured with a single exploit script and a README, and is intended for educational and testing purposes.
This repository contains a proof-of-concept exploit for CVE-2025-31131, a high-severity unauthenticated path traversal vulnerability in YesWiki versions prior to 4.5.2. The exploit consists of a single Python script ('exploit.py') and a README.md file. The script allows an attacker to read arbitrary files from the server by exploiting the 'squelette' parameter in a crafted HTTP GET request. The script supports both single-target and bulk scanning modes, with multithreading for efficiency. The default file targeted is '/etc/passwd', but any file path can be specified. The exploit does not require authentication and is effective against any vulnerable YesWiki instance accessible over the network. The repository is well-structured, with clear usage instructions and a detailed description of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.