{"schema_version":"1.7.3","id":"GHSA-5m9m-j5p7-m7f9","published":"2025-10-08T21:30:34Z","modified":"2025-11-05T19:57:10.988637Z","aliases":["CVE-2025-61524","GO-2025-4026"],"summary":"Casdoor is vulnerable to Improper Authorization","details":"An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.","affected":[{"package":{"name":"github.com/casdoor/casdoor","ecosystem":"Go","purl":"pkg:golang/github.com/casdoor/casdoor"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.63.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-5m9m-j5p7-m7f9/GHSA-5m9m-j5p7-m7f9.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61524"},{"type":"WEB","url":"https://github.com/casdoor/casdoor/commit/d883db907bb6e0b95737ef8e8b57b7da9078cbdd"},{"type":"WEB","url":"https://gist.github.com/DevHjz/e75cea851d48e5f5478ac2a90757851a"},{"type":"PACKAGE","url":"https://github.com/casdoor/casdoor"},{"type":"WEB","url":"https://github.com/casdoor/casdoor/releases/tag/v2.63.0"},{"type":"WEB","url":"http://casdoor.com"}],"database_specific":{"cwe_ids":["CWE-285"],"github_reviewed":true,"github_reviewed_at":"2025-10-14T20:12:38Z","nvd_published_at":"2025-10-08T19:15:44Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}