CVE-2025-66410

G

in-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.

Configurations

Configuration 1 (hide)

cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*

History

06 Feb 2026, 16:50

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*
First Time Gin-vue-admin Project
Gin-vue-admin Project gin-vue-admin
References () https://github.com/flipped-aurora/gin-vue-admin/commit/ee8d8d7e04d9c38a35a6969f20e75213e84f57c6 - () https://github.com/flipped-aurora/gin-vue-admin/commit/ee8d8d7e04d9c38a35a6969f20e75213e84f57c6 - Patch
References () https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-jrhg-82w2-vvj7 - () https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-jrhg-82w2-vvj7 - Exploit, Vendor Advisory

01 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 23:15

Updated : 2026-02-06 16:50


NVD link : CVE-2025-66410

Mitre link : CVE-2025-66410

CVE.ORG link : CVE-2025-66410


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')