CVE-2025-65952

HIGH

Console <2.8.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the Gorilla Tag path and write to unwanted directories. This issue has been patched in version 2.8.0.

Scores

CVSS v4 8.7
EPSS 0.0010
EPSS Percentile 26.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
iiDk-the-actual/Console < 2.8.0
Published Nov 25, 2025
Tracked Since Feb 18, 2026