CVE-2025-61188: Jeecg Boot

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

Affected products

  • Jeecg Jeecg Boot: up to and including 3.8.2

Published 2025-10-01. Last modified 2026-06-17.