CVE-2025-65952
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-25

Last updated on: 2025-11-25

Assigner: GitHub, Inc.

Description
Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched in version 2.8.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-25
Last Modified
2025-11-25
Generated
2026-06-16
AI Q&A
2025-11-26
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
gorillatag gorillatag *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the Console network used to control Gorilla Tag mods and users. Before version 2.8.0, attackers could use complex combinations of backslashes and periods to escape the intended Gorilla Tag directory path and write files to unauthorized directories on the system. This could allow unauthorized modification of files outside the intended scope.

Impact Analysis

The vulnerability can allow an attacker to write files to unintended directories on the system, potentially leading to unauthorized data modification, system compromise, or disruption of normal operations. This could result in loss of data integrity or availability.

Mitigation Strategies

Upgrade the Console software to version 2.8.0 or later, as this version contains the patch that fixes the path traversal vulnerability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-65952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart