CVE-2025-55149 | ulab-uiuc tiny-scientist up to 0.1.1 PDF File backend/app.py review_paper path traversal (GHSA-rrgf-hcr9-jq6h / EUVD-2025-24027)
A vulnerability, which was classified as critical, was found in ulab-uiuc tiny-scientist up to 0.1.1. This affects the function review_paper of the file backend/app.py of the component PDF File Handler. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-55149. It is possible to initiate the attack remotely. There is no exploit available.