CVE-2025-24886 - CVE House
Back to Database
Status published High CVE-2025-24886

pwn.college has Symlink LFI in Dojo repos

Vulnerability Description

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Incorrect symlink checks on user specified dojos allows for users (admin not required) to perform an LFI from the CTFd container. When a user clones or updates repositories, a check is performed to see if the repository had contained any symlinks. A malicious user could craft a repository with symlinks pointed to sensitive files and then retrieve them using the CTFd website.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24886

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dojo
Vulnerable Versions:
<= 613e4fd654b16e5e0888e9205702bde83de91c60

Timeline

Official Publish: January 30th, 2025
Last Modified: January 31st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Weaknesses (CWE)