PT-2025-27253 · Sublinkx · Sublinkx
Tritium
·
Published
2025-06-27
·
Updated
2025-06-28
·
CVE-2025-6774
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
gooaclok819 sublinkX versions up to 1.8
Description:
A critical issue has been found, affecting the function
AddTemp of the file api/template.go. The manipulation of the argument filename leads to path traversal. This issue can be exploited remotely. Upgrading to version 1.9 addresses this issue.Recommendations:
For versions up to 1.8, upgrade to version 1.9 to resolve the issue. As a temporary workaround, consider restricting the use of the
AddTemp function in the api/template.go file until the upgrade is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sublinkx