CVE-2025-66410
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
01/12/2025
Last modified:
06/02/2026
Description
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:gin-vue-admin_project:gin-vue-admin:*:*:*:*:*:*:*:* | 2.8.6 (including) |
To consult the complete list of CPE names with products and versions, see this page



