CVE-2025-66410

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Dec 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-01 23:15

Updated : 2025-12-02 17:16


NVD link : CVE-2025-66410

Mitre link : CVE-2025-66410

CVE.ORG link : CVE-2025-66410


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')