| id: GO-2025-4026 |
| modules: |
| - module: github.com/casdoor/casdoor |
| non_go_versions: |
| - fixed: 2.63.0 |
| vulnerable_at: 1.1000.0 |
| summary: Casdoor is vulnerable to Improper Authorization in github.com/casdoor/casdoor |
| cves: |
| - CVE-2025-61524 |
| ghsas: |
| - GHSA-5m9m-j5p7-m7f9 |
| references: |
| - advisory: https://github.com/advisories/GHSA-5m9m-j5p7-m7f9 |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-61524 |
| - fix: https://github.com/casdoor/casdoor/commit/d883db907bb6e0b95737ef8e8b57b7da9078cbdd |
| - web: http://casdoor.com |
| - web: https://gist.github.com/DevHjz/e75cea851d48e5f5478ac2a90757851a |
| - web: https://github.com/casdoor/casdoor/releases/tag/v2.63.0 |
| source: |
| id: GHSA-5m9m-j5p7-m7f9 |
| created: 2025-10-28T17:37:10.310350876Z |
| review_status: UNREVIEWED |