GHSA-g4mf-96x5-5m2c · Severity: high · Ecosystem: npm — Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead to a variety of malicious outcomes, such as bypassing security checks, altering data, or manipulating the application's behavior. **Note:** Following our established security policy, we attempted to contact the maintainer regarding this vulnerability, but haven't received a response.
Conclusion & alert: CVE-2025-12613 is rated Moderate Risk (41.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-20 | 0.05% | 0.06% | +0.01% |
| 2 | 2026-04-08 | 0.06% | 0.05% | -0.01% |
| 3 | 2025-11-16 | — | 0.06% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 4.0 | HIGH |
|
— | — | [email protected] |
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.7 | [email protected] |
GHSA-g4mf-96x5-5m2c · Severity: high · Ecosystem: npm — Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||