CVE-2025-61524
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login
02 / AFFECTED SOFTWARE
Affected packages
1396 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login
Casdoor is vulnerable to Improper Authorization in github.com/casdoor/casdoor. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/casdoor/casdoor before v2.63.0.
An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.
05 / REFERENCES
Further evidence
- https://gist.github.com/DevHjz/e75cea851d48e5f5478ac2a90757851a
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61524.json
- https://github.com/casdoor/casdoor/commit/d883db907bb6e0b95737ef8e8b57b7da9078cbdd
- https://github.com/casdoor/casdoor/releases/tag/v2.63.0
- https://nvd.nist.gov/vuln/detail/CVE-2025-61524
- http://casdoor.com
- https://github.com/advisories/GHSA-5m9m-j5p7-m7f9
- https://github.com/casdoor/casdoor