CVE-2025-23410CRITICAL 9.8EPSS p44.5%
CVE-2025-23410CVE-2025-23410
Description
When uploading organism or sequence data via the web interface,
GMOD Apollo
will unzip and inspect the files and will not check for path
traversal in supported archive types.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.61% probability of exploitation · percentile 44.5% · 2026-06-18T12:00:27Z |
| Published | 2025-03-05 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Relative Path Traversalcwe-23 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.