CVE-2025-50736
Last modified
CVE-2025-50736 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security filters.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websites via the file parameter to the /gradio_api endpoint. This vulnerability could be exploited for phishing attacks or to bypass security filters.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-50736?
How severe is CVE-2025-50736?
How do I fix CVE-2025-50736?
Are you affected by CVE-2025-50736?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
