Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
pypi package report
Is casdoor safe?
2 known vulnerabilities, worst severity CRITICAL.
// reach
0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage
No published models are known to use this package.
cvss
0.0
critical
severity band, no base score published
epss
0.00%
medium
chance of exploitation in 30 days, 68th percentile of all CVEs
xyz score
0.0
medium
CyberXYZ composite out of 10
fig. 01 — GHSA-9vm3-r8gq-cr6x, the advisory selected below
// 2 advisories
Checked 2026-10-06 at 02:05 UTC. The most recent advisory here was published 2022-09-09. Updated continuously from NVD, GHSA, OSV and CNA feeds.