CVE-2025-61524: High severity Casdoor Casdoor vulnerability

Published Oct 8, 2025
·
Updated

An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.

Other sources

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login

NVD

Affected Software

3 affected componentsFixes available
Casdoor Casdoor<2.26.0
Casdoor Casdoor<=2.26.0
go/github.com/casdoor/casdoor<2.63.0
2.63.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/casdoor/casdoor to a version that resolves this vulnerability.

    Fixed in 2.63.0
  2. Upgrade

    Upgrade Casdoor to a version that resolves this vulnerability.

    Fixed in 2.63.0

Event History

Oct 8, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-61524?

CVE-2025-61524 has a medium severity rating due to its impact on permission verification allowing unauthorized access.

2

How do I fix CVE-2025-61524?

To fix CVE-2025-61524, upgrade to Casdoor version 2.63.0 or later.

3

Who is affected by CVE-2025-61524?

CVE-2025-61524 affects remote authenticated administrators of any organization using Casdoor versions before 2.63.0.

4

What are the potential consequences of CVE-2025-61524?

The potential consequences of CVE-2025-61524 include unauthorized access to sensitive organization/application settings.

5

Is CVE-2025-61524 an exploit or an information disclosure?

CVE-2025-61524 is classified as an exploit that allows bypassing of permission verification mechanisms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203