CVE-2025-23410: Gmod Apollo

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types.

Affected products

  • Gmod Apollo: before 2.8.0 (fixed in 2.8.0)

Published 2025-03-05. Last modified 2026-06-17.