Local File Inclusion Vulnerability in Pwn.college Education Platform
CVE-2025-24886
What is CVE-2025-24886?
The Pwn.college education platform exhibits a Local File Inclusion vulnerability caused by improper symlink checks on user-specified dojos. This flaw enables an attacker to exploit the behavior when cloning or updating repositories. A malicious user can create a repository with symlinks pointing to sensitive files, and through the CTFd interface, retrieve those files without requiring administrative privileges. This vulnerability poses a significant risk to the integrity and confidentiality of sensitive data within the platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dojo <= 613e4fd654b16e5e0888e9205702bde83de91c60
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
