CVE-2025-60020: Nncp

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

Affected products

  • Nncp Nncp: before 8.12.0 (fixed in 8.12.0)

Published 2025-09-24. Last modified 2026-06-17.