{"id":"GHSA-5m9m-j5p7-m7f9","summary":"Casdoor is vulnerable to Improper Authorization","details":"An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.","aliases":["CVE-2025-61524","GO-2025-4026"],"modified":"2025-11-05T19:58:34.048105Z","published":"2025-10-08T21:30:34Z","database_specific":{"github_reviewed_at":"2025-10-14T20:12:38Z","nvd_published_at":"2025-10-08T19:15:44Z","cwe_ids":["CWE-285"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61524"},{"type":"WEB","url":"https://github.com/casdoor/casdoor/commit/d883db907bb6e0b95737ef8e8b57b7da9078cbdd"},{"type":"WEB","url":"https://gist.github.com/DevHjz/e75cea851d48e5f5478ac2a90757851a"},{"type":"PACKAGE","url":"https://github.com/casdoor/casdoor"},{"type":"WEB","url":"https://github.com/casdoor/casdoor/releases/tag/v2.63.0"},{"type":"WEB","url":"http://casdoor.com"}],"affected":[{"package":{"name":"github.com/casdoor/casdoor","ecosystem":"Go","purl":"pkg:golang/github.com/casdoor/casdoor"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.63.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-5m9m-j5p7-m7f9/GHSA-5m9m-j5p7-m7f9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}