Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Sep 10, 2025
rAthena has SQL Injection in PartyBooking component via `WorldName` parameter.
CVE-2025-58448
Description
rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking component via WorldName parameter. Commit 0d89ae0 fixes the issue.
Affected products
2- rathena/rathenav5Range: < 0d89ae0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/rathena/rathena/commit/0d89ae071ff5e46e8dedcf45d060acec84b3abb5mitrex_refsource_MISC
- github.com/rathena/rathena/security/advisories/GHSA-x99j-36m7-4vv7mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.