{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-62182", "assignerOrgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "state": "PUBLISHED", "assignerShortName": "Pega", "dateReserved": "2025-10-07T19:04:27.220Z", "datePublished": "2026-01-13T16:37:06.709Z", "dateUpdated": "2026-06-03T19:46:43.439Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "c91e5604-2bd1-401f-a0ec-b25342b57ef9", "shortName": "Pega", "dateUpdated": "2026-06-03T19:46:43.439Z" }, "title": "Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.", "datePublic": "2026-01-13T16:30:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-434", "description": "CWE-434: Unrestricted Upload of File with Dangerous Type", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-1", "descriptions": [ { "lang": "en", "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs" } ] } ], "affected": [ { "vendor": "Pegasystems", "product": "Pega Infinity", "versions": [ { "status": "affected", "version": "8.7.0", "lessThan": "Infinity 25.1.1", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "