CVE-2025-61189: Path Traversal
Published Oct 1, 2025
·Updated
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.
Affected Software
2 affected components
JeecgBoot JeecgBoot<3.8.2
Jeecg jeecg boot<=3.8.2
Event History
Oct 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61189?
CVE-2025-61189 is classified as a critical severity path traversal vulnerability.
2
How do I fix CVE-2025-61189?
To fix CVE-2025-61189, update Jeecgboot to version 3.8.3 or later.
3
What are the consequences of exploiting CVE-2025-61189?
Exploiting CVE-2025-61189 allows attackers to upload files to sensitive system directories, potentially leading to code execution.
4
Which versions of Jeecgboot are affected by CVE-2025-61189?
CVE-2025-61189 affects Jeecgboot versions 3.8.2 and earlier.
5
What endpoint is associated with CVE-2025-61189?
The endpoint associated with CVE-2025-61189 is /sys/comment/addFile.