CVE-2025-23410
When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.65%
- CWE
- CWE-23
- Published
- 2025-03-04
- Last modified
- 2026-03-13
Affected products
- GMOD Apollo
Weakness type
Related vulnerabilities
- CVE-2026-84939 — Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
- CVE-2026-15913 — Path Traversal in Fortra's GoAnywhere MFT Endpoint
- CVE-2026-79728 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87747 — Ragic|Enterprise Cloud Database - Arbitrary File Read
- CVE-2026-47680 — Source controller: Improper path handling allows traversal
- CVE-2026-77897 — Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
- CVE-2026-72948 — Windows DNS Elevation of Privilege Vulnerability
- CVE-2026-67367 — A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE...