CVE 10 CRITICAL

Directory Traversal in Robocode’s CacheCleaner Component_CVE-2025-14306

10 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red

Description

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file deletions. https://robo-code.blogspot.com/

Basic Information

ID CVE-2025-14306
Source GovTech CSG
Published Dec 9, 2025 at 07:19

Affected Product

Vendor Robocode Project
Product Robocode
Version 1.9.3.6
Affected Versions Robocode Project Robocode 1.9.3.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.