CVE-2025-9409 | lostvip-com ruoyi-go up to 2.1 CommonController.go DownloadTmp/DownloadUpload fileName path traversal
A vulnerability was found in lostvip-com ruoyi-go up to 2.1. It has been classified as critical. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system/controller/CommonController.go. Performing manipulation of the argument fileName results in path traversal.
This vulnerability is cataloged as CVE-2025-9409. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.