CVE-2025-66410

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*

History

06 Feb 2026, 16:50

Type Values Removed Values Added
First Time Gin-vue-admin Project gin-vue-admin
Gin-vue-admin Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:*
References () https://github.com/flipped-aurora/gin-vue-admin/commit/ee8d8d7e04d9c38a35a6969f20e75213e84f57c6 - () https://github.com/flipped-aurora/gin-vue-admin/commit/ee8d8d7e04d9c38a35a6969f20e75213e84f57c6 - Patch
References () https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-jrhg-82w2-vvj7 - () https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-jrhg-82w2-vvj7 - Exploit, Vendor Advisory

01 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 23:15

Updated : 2026-02-06 16:50


NVD link : CVE-2025-66410

Mitre link : CVE-2025-66410

CVE.ORG link : CVE-2025-66410


JSON object : View

Products Affected

gin-vue-admin_project

  • gin-vue-admin
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')