CVE-2025-66480 | wildfirechat im-server up to 1.4.2 Endpoint /fs writeFileUploadData path traversal (GHSA-74hq-jhx2-fq6c)
A vulnerability classified as critical was found in wildfirechat im-server up to 1.4.2. Affected is the function writeFileUploadData of the file /fs of the component Endpoint. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2025-66480. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.