A vulnerability classified as critical was found in Apache IoTDB up to 1.3.5/2.0.5. Affected by this issue is some unknown functionality. Such manipulation leads to path traversal.

This vulnerability is referenced as CVE-2025-55017. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.