CVE-2020-25074: Debian Linux

Critical severity, CVSS 9.8. EPSS: 6.6% chance of exploitation in the next 30 days.

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Moinmo Moinmoin: up to and including 1.9.10

Published 2020-11-10. Last modified 2026-06-17.