{"id":"CVE-2025-13593","title":"Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.","summary":"Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","cwe":["CWE-346"],"vendor":"synology","product":"activeprotect_agent","affected":["activeprotect_agent < 1.1.0-0439"],"patched":["activeprotect_agent 1.1.0-0439"],"published":"2026-05-27","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:10:00.190","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13593","references":[{"url":"https://www.synology.com/en-global/security/advisory/Synology_SA_25_15","label":"security@synology.com"}],"tags":["nvd"],"epss":0.00086,"epssPercentile":0.00299,"ingestedAt":"2026-09-30T21:25:07.733Z","slug":"CVE-2025-13593","body":"## Overview\n\nOrigin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.\n\n## Affected\n\n- `activeprotect_agent < 1.1.0-0439`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `activeprotect_agent 1.1.0-0439`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}