CVE-2025-61514 Details
Description
An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.
A vulnerability allowing arbitrary file uploads has been identified in SageMath, Inc CoCalc versions prior to the patch in commit 0d2ff58. This vulnerability allows attackers to execute arbitrary code by uploading a specially crafted SVG file. The issue arises from improper input validation and unrestricted file uploads of dangerous file types, which can lead to stored cross-site scripting (XSS) vulnerabilities.
Users should update to the latest version of CoCalc, which includes the patch for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 16, 2025CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-61514 | [email protected] | ExploitTechnical Description |
| https://github.com/sagemathinc/cocalc | [email protected] | ProductVendor |
| https://github.com/sagemathinc/cocalc/commit/0d2ff5890a3ae62e941aad8a5884dd765b7e98fc | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SageMath CoCalc | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | [email protected] |
Volerion