PT-2025-48096 · Unknown · Gorilla Tag

Published

2025-11-25

·

Updated

2025-11-26

·

CVE-2025-65952

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gorilla Tag versions prior to 2.8.0
Description A path traversal issue exists in Console, a network used to control Gorilla Tag mods and users. Prior to version 2.8.0, specific combinations of backslashes and periods can be used to bypass the Gorilla Tag path and write to unintended directories.
Recommendations Update to version 2.8.0 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-65952
GHSA-C3F7-XH45-2XC7

Affected Products

Gorilla Tag