---
id: CVE-2025-11842
title: A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1
summary: >-
  A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1.
  The impacted element is an unknown function of the component Bundle Handler.
  The manipulation of the argument Version leads to path traversal. Remote
  exploitatio…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-22
published: '2025-10-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11842'
references:
  - url: 'https://github.com/Shazwazza/Smidge/releases/tag/v4.6.0'
    label: cna@vuldb.com
  - url: 'https://github.com/asust9/smidge-vuln?tab=readme-ov-file'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328776'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328776'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664905'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00434
epssPercentile: 0.35715
ingestedAt: '2026-10-09T12:53:28.985Z'
---

## Overview

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The manipulation of the argument Version leads to path traversal. Remote exploitation of the attack is possible. Upgrading to version 4.6.0 is sufficient to resolve this issue. It is recommended to upgrade the affected component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
