Critical severity9.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2025-65602
CVE-2025-65602
Description
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689nvdPermissions Required
- www.notion.so/ChanCMS-Unauthenticated-RCE-2a3ee9235ba380fc9973e16c06258689nvdPermissions Required
News mentions
0No linked articles in our index yet.