CVE-2025-64176 describes an arbitrary file upload vulnerability in ThinkDashboard versions 0.6.7 and below, affecting the self-hosted bookmark dashboard built with Go and vanilla JavaScript. An unauthenticated attacker can bypass client-side file type verification during backup import to upload any file to the /data directory. This medium-severity vulnerability (CVSS 6.1) has a network attack vector and low attack complexity, potentially leading to stored Cross-Site Scripting (XSS) or malware distribution. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.6.8CPE matchmatch criteria | cpe:2.3:a:matiasdesuu:thinkdashboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.