# CVE-2025-24886

## Summary

- **CVE ID:** CVE-2025-24886
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-61, CWE-200
- **Published:** Jan 30, 2025
- **Last Modified:** Mar 12, 2026

## Description

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website.

## Affected Products

- pwncollege — dojo (<= 613e4fd654b16e5e0888e9205702bde83de91c60)

## References

- [CNA](https://github.com/pwncollege/dojo/security/advisories/GHSA-fcq8-jqq5-9xmh)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.47%
- **EPSS Percentile:** 39.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._