Metrics
Affected Vendors & Products
Mon, 09 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:altumcode:66biolinks:44.0.0:*:*:*:*:*:*:* |
Mon, 02 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 29 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Altumcode
Altumcode 66biolinks |
|
| Vendors & Products |
Altumcode
Altumcode 66biolinks |
Wed, 28 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-01-28T00:00:00.000Z
Updated: 2026-02-02T15:51:24.053Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69601
Updated: 2026-01-29T18:37:59.537Z
Status : Analyzed
Published: 2026-01-28T19:16:23.910
Modified: 2026-02-09T17:25:23.750
Link: CVE-2025-69601
No data.