CVE-2025-32950 | Jmix up to 1.6.1/2.3.4 /files FileRef path traversal (GHSA-jx4g-3xqm-62vh)
A vulnerability was found in Jmix up to 1.6.1/2.3.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /files. The manipulation of the argument FileRef leads to path traversal: '.../...//'.
This vulnerability is handled as CVE-2025-32950. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.