CVE-2020-25074: Debian Linux
Critical severity, CVSS 9.8. EPSS: 6.6% chance of exploitation in the next 30 days.
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
Affected products
Published 2020-11-10. Last modified 2026-06-17.