CVE-2025-2954 | mannaandpoem OpenManus up to 2025.3.13 File app/tool/file_saver.py execute access control
A vulnerability, which was classified as problematic, was found in mannaandpoem OpenManus up to 2025.3.13. This affects the function execute of the file app/tool/file_saver.py of the component File Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-2954. Local access is required to approach this attack. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.