CVE-2025-9650 Overview
CVE-2025-9650 is a path traversal vulnerability [CWE-22] in the yeqifu carRental application. The flaw resides in the removeFileByPath function within src/main/java/com/yeqifu/sys/utils/AppFileUtils.java. Attackers manipulate the carimg argument to traverse directories and delete arbitrary files on the host. The issue affects yeqifu carRental up to commit 3fabb7eae93d209426638863980301d6f99866b3. Because the project follows a rolling release strategy, no fixed version identifier is published. The exploit has been publicly disclosed and can be executed remotely by an authenticated low-privilege user.
Critical Impact
Remote authenticated attackers can delete arbitrary files on the server by supplying crafted path values to the carimg parameter, potentially disrupting application integrity and availability.
Affected Products
- yeqifu carRental up to commit 3fabb7eae93d209426638863980301d6f99866b3
- Component: AppFileUtils.java — function removeFileByPath
- Rolling release distribution (no discrete versioned patch)
Discovery Timeline
- 2025-08-29 - CVE-2025-9650 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9650
Vulnerability Analysis
The vulnerability originates in the removeFileByPath helper inside AppFileUtils.java. The function accepts a user-controlled carimg argument and uses it to construct a file path targeted for deletion. Because the value is not canonicalized or restricted to an allow-listed directory, attackers can inject relative traversal sequences such as ../ to escape the intended upload directory. Successful exploitation deletes files outside the application's designated storage area. Removal of configuration files, logs, or dependent assets can cause the application to malfunction and complicate forensic recovery.
Root Cause
The root cause is insufficient input validation on the carimg parameter before passing it to file deletion logic. The function trusts the supplied path without normalizing it via File.getCanonicalPath() or verifying containment within an approved base directory. This classic path traversal weakness maps to CWE-22, Improper Limitation of a Pathname to a Restricted Directory.
Attack Vector
Exploitation requires network access and a low-privilege authenticated session against the carRental application. An attacker submits a request to the endpoint that invokes removeFileByPath, supplying a carimg value containing directory traversal sequences that resolve to a sensitive file outside the upload folder. No user interaction is needed to complete the deletion. Public disclosure references indicate the technique is documented and reproducible against affected commits.
See the GitHub CVE-File Documentation for proof-of-concept details and the VulDB entry #321858 for additional context.
Detection Methods for CVE-2025-9650
Indicators of Compromise
- Requests to carRental endpoints containing carimg parameter values with ../, ..\, or URL-encoded traversal sequences such as %2e%2e%2f.
- Unexpected deletion of files outside the configured upload directory, including configuration, log, or static asset files.
- Application errors or missing-resource exceptions correlating with prior HTTP requests referencing removeFileByPath code paths.
Detection Strategies
- Inspect application access logs for parameter values that contain traversal tokens or absolute paths targeting system directories.
- Enable file integrity monitoring on the carRental installation directory and any adjacent paths reachable via traversal.
- Correlate authentication events with subsequent file-deletion API activity to identify abuse by low-privilege accounts.
Monitoring Recommendations
- Alert on HTTP requests where the carimg parameter contains characters outside an approved filename allow-list.
- Monitor filesystem audit logs for deletion events on paths outside the carRental upload directory.
- Track anomalous rates of file deletion operations originating from the carRental service account.
How to Mitigate CVE-2025-9650
Immediate Actions Required
- Restrict network access to the carRental application to trusted users while remediation is applied.
- Audit application logs for prior invocations of removeFileByPath with suspicious carimg values and inventory any missing files.
- Rotate application credentials if abuse of low-privilege accounts is suspected.
Patch Information
The project follows a rolling release strategy and no discrete patched version is enumerated in the advisory. Operators should track the upstream yeqifu carRental repository for commits that add canonical path validation to AppFileUtils.removeFileByPath and rebuild from a commit later than 3fabb7eae93d209426638863980301d6f99866b3 once a fix lands.
Workarounds
- Add server-side validation that rejects carimg values containing /, \, .., null bytes, or URL-encoded equivalents.
- Canonicalize the resolved file path with File.getCanonicalPath() and confirm it starts with the approved upload directory before invoking deletion.
- Run the carRental process under a least-privilege OS account that lacks write access to configuration and system directories.
# Example WAF rule fragment to block traversal in the carimg parameter
SecRule ARGS:carimg "@rx (\.\./|\.\.\\|%2e%2e%2f|%2e%2e%5c)" \
"id:1009650,phase:2,deny,status:400,log,msg:'CVE-2025-9650 path traversal attempt in carimg'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
