Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
References
Configurations
History
06 Feb 2026, 16:50
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Gin-vue-admin Project gin-vue-admin
Gin-vue-admin Project |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CPE | cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:* | |
| References | () https://github.com/flipped-aurora/gin-vue-admin/commit/ee8d8d7e04d9c38a35a6969f20e75213e84f57c6 - Patch | |
| References | () https://github.com/flipped-aurora/gin-vue-admin/security/advisories/GHSA-jrhg-82w2-vvj7 - Exploit, Vendor Advisory |
01 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 23:15
Updated : 2026-02-06 16:50
NVD link : CVE-2025-66410
Mitre link : CVE-2025-66410
CVE.ORG link : CVE-2025-66410
JSON object : View
Products Affected
gin-vue-admin_project
- gin-vue-admin
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
