CVE-2025-65952

Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched in version 2.8.0.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Nov 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 23:15

Updated : 2025-12-01 15:39


NVD link : CVE-2025-65952

Mitre link : CVE-2025-65952

CVE.ORG link : CVE-2025-65952


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')