CVE-2025-57631
Critical · CVSS 9.8TDuckCloud tduck-platform — SQL Injection RCE via file upload module
- CVSS
- 9.8
- nvd
- EPSS
- 0.76%
- 52th pct
- KEV
- No
- Class
- oss containerizable
- CWE-89
Description
SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module
Search profile — drives PoC discovery
Symbols tduck-platformAdd a file upload modulefile uploadSQL InjectionTDuckCloudtduck
Keywords CVE-2025-57631TDuckCloudtduck-platformSQL injectionfile upload modulev5.1arbitrary code executionCWE-89
Versions: v5.1
References
Status: enriched · ingested 2026-07-05T00:00:39.000Z · profiled 2026-07-05T00:30:39.000Z