CVE-2025-27106

HIGH

binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a com...

Affects 0 products across 1 vendor.

BCS6.96
CVSS 3.18.8
CVSS v47.7
EPSS2.0%
Percentile79th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A high severity vulnerability affects Binance systems (CVE-2025-27106). No public exploit code is currently available. Apply available vendor patches promptly.

BSID: BS-2025-GLOBAL-248644-H • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-27106?
A high severity vulnerability affects Binance systems (CVE-2025-27106). No public exploit code is currently available. Apply available vendor patches promptly.
What is the CVSS score for CVE-2025-27106?
CVE-2025-27106 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.0%.
Is CVE-2025-27106 actively exploited?
No confirmed active exploitation of CVE-2025-27106 as of 2026-05-30.
How do I remediate CVE-2025-27106?
Priority: MEDIUM.
What systems are affected by CVE-2025-27106?
CVE-2025-27106 affects: Binance.
Vulnerability Details
CVE IDCVE-2025-27106
BSIDBS-2025-GLOBAL-248644-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2025-02-21
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot is vulnerable to command injection via the `/restore` endpoint. The name of the uploaded file is passed to shell.exec without sanitization other than path normalization, resulting in Remote Code Execution. This may allow any authorized user to execute code in the context of the host machine. This issue has been addressed in version 0.0.100 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a command injection vulnerability in the `/restore` endpoint. The restore endpoint of binance-trading-bot is vulnerable to command injection via the `/restore` endpoint. The name of the uploaded file is passed to shell.exec without sanitization other than path normalization, resulting in Remote Code Executi CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Binance —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 518 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash8105f6a07590a5606198a5259243a38b2dd8e7eef0e8ad23f0f475043c2e09b3d69a669584adb5ea8f905c190f09da9864b709f4f2580eeaddbacdb6398d1950
Related CVEs affecting Binance
CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2020-12118 8.2 The keygen protocol implementation in Binance tss-lib before 1.2.0 allows att... CVE-2024-23660 7.5 The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd14436...
View all Binance CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →