---
id: CVE-2014-3225
aliases:
  - GHSA-xc7w-jvhx-p6q9
  - PYSEC-2026-797
title: Cobbler Path Traversal vulnerability
summary: Cobbler Path Traversal vulnerability
severity: medium
vendor: cobbler
product: cobbler
ecosystem: pip
affected:
  - 'cobbler >= 2.6.0, < 2.6.4'
  - 'cobbler >= 2.4.0, < 2.4.7'
patched:
  - cobbler 2.6.4
  - cobbler 2.4.7
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-xc7w-jvhx-p6q9'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2014-3225'
  - url: 'https://github.com/cobbler/cobbler/issues/939'
  - url: >-
      https://github.com/cobbler/cobbler/commit/8232c0e88ec7382d3f8d3bf48c81a4a91ac4325d
  - url: >-
      https://github.com/cobbler/cobbler/commit/f757e3096fcd32397609ca38efb01f19d16dd634
  - url: 'https://github.com/cobbler/cobbler'
  - url: 'https://www.youtube.com/watch?v=vuBaoQUFEYQ&feature=youtu.be'
  - url: >-
      http://packetstormsecurity.com/files/126553/Cobbler-Local-File-Inclusion.html
  - url: 'http://seclists.org/oss-sec/2014/q2/273'
  - url: 'http://seclists.org/oss-sec/2014/q2/274'
  - url: 'http://www.exploit-db.com/exploits/33252'
  - url: 'http://www.osvdb.org/106759'
  - url: 'http://www.securityfocus.com/archive/1/532094/100/0/threaded'
  - url: 'http://www.securityfocus.com/bid/67277'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.08881
epssPercentile: 0.95044
exploitAvailable: true
ingestedAt: '2026-07-08T18:25:54.168Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-21T15:24:37.566Z'
---

## Overview

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

## Affected packages

- `cobbler >= 2.6.0, < 2.6.4`
- `cobbler >= 2.4.0, < 2.4.7`

## Remediation

Upgrade to a patched release:

- `cobbler 2.6.4`
- `cobbler 2.4.7`
