CVE-2025-6774
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
27/06/2025
Last modified:
15/04/2026
Description
A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been rated as critical. Affected by this issue is the function AddTemp of the file api/template.go. The manipulation of the argument filename leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9 is able to address this issue. The patch is identified as 778d26aef723daa58df98c8060c43f5bf5d1b10b. It is recommended to upgrade the affected component.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/gooaclok819/sublinkX/commit/778d26aef723daa58df98c8060c43f5bf5d1b10b
- https://github.com/gooaclok819/sublinkX/issues/68#issuecomment-2957290524
- https://github.com/gooaclok819/sublinkX/issues/69
- https://github.com/gooaclok819/sublinkX/releases/tag/1.9
- https://vuldb.com/?ctiid.314090
- https://vuldb.com/?id.314090
- https://vuldb.com/?submit.602369



