PT-2025-48577 · Unknown · Gin-Vue-Admin

Published

2025-12-01

·

Updated

2026-02-06

·

CVE-2025-66410

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gin-vue-admin versions prior to 2.8.6
Description Gin-vue-admin, a backstage management system based on vue and gin, is affected by a file deletion issue. Attackers can delete any file on the server, potentially causing damage or unavailability of server resources. This is achieved by manipulating the FileMd5 parameter.
Recommendations Update Gin-vue-admin to version 2.8.6 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66410
GHSA-JRHG-82W2-VVJ7
GO-2025-4171
SUSE-SU-2025:4395-1

Affected Products

Gin-Vue-Admin