dreamfactory/df-core
DreamFactory is a self-hosted platform providing governed API access to any data source for enterprise apps and local LLMs.
Activity
- Latest release
- 1mo ago
- Total releases
- 124
- Cadence
- ~34 days
- Last 12 months
- 8
Reach
- Stars
- 16
Details
- License
- Apache-2.0
- First release
- Aug 04, 2015
| Version | Released | |
|---|---|---|
1.0.17
patch
| ||
1.0.16
patch
| ||
1.0.15
patch
| ||
1.0.14
patch
| ||
1.0.13
patch
| ||
1.0.12
patch
| ||
1.0.11
patch
| ||
1.0.10
patch
| ||
1.0.9
patch
| ||
1.0.8
patch
| ||
1.0.7
patch
| ||
1.0.6
patch
| ||
1.0.5
patch
| ||
1.0.4
patch
| ||
1.0.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.25.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.25.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.25.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.25.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.24.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.23.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.22.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.22.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.22.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.21.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.20.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.19.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.19.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.19.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.18.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.17.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.16.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.16.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.16.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.16.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.15.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.15.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.15.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.15.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.14.3
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.14.2
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.12.4
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.14.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2025-55988
GHSA-gv7f-w92j-383q
Mar 20, 2026
DreamFactory has a directory traversal
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path. Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.2
0.0.3
0.0.4
0.0.5
+ 98 more Show less
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.10.0
0.11.0
0.11.1
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.14.0
0.14.1
0.14.2
0.14.3
0.15.0
0.15.1
0.15.2
0.15.3
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.18.0
0.19.0
0.19.1
0.19.2
0.2.0
0.2.1
0.2.10
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
0.20.0
0.21.0
0.21.1
0.22.0
0.22.1
0.22.2
0.22.3
0.23.0
0.24.0
0.25.0
0.25.1
0.25.2
0.25.3
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
1.0.3
Fixed in
1.0.4
References
Updated Mar 20, 2026 · Source: OSV.dev |