CVE-2025-27106
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a com...
Affects 0 products across 1 vendor.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A high severity vulnerability affects Binance systems (CVE-2025-27106). No public exploit code is currently available. Apply available vendor patches promptly.
BSID: BS-2025-GLOBAL-248644-H • Model: rule-based-v1 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-27106?
What is the CVSS score for CVE-2025-27106?
Is CVE-2025-27106 actively exploited?
How do I remediate CVE-2025-27106?
What systems are affected by CVE-2025-27106?
| CVE ID | CVE-2025-27106 |
|---|---|
| BSID | BS-2025-GLOBAL-248644-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Published | 2025-02-21 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot is vulnerable to command injection via the `/restore` endpoint. The name of the uploaded file is passed to shell.exec without sanitization other than path normalization, resulting in Remote Code Execution. This may allow any authorized user to execute code in the context of the host machine. This issue has been addressed in version 0.0.100 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot is vulnerable to command injection via the `/restore` endpoint. The name of the uploaded file is passed to shell.exec without sanitization other than path normalization, resulting in Remote Code Executi CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Exploitation Likelihood: MINIMAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Binance | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 8105f6a07590a5606198a5259243a38b2dd8e7eef0e8ad23f0f475043c2e09b3d69a669584adb5ea8f905c190f09da9864b709f4f2580eeaddbacdb6398d1950 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →