---
id: CVE-2025-69904
title: >-
  Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an
  administrator to read arbitrary files on the server by manipulating file path
  input
summary: >-
  Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an
  administrator to read arbitrary files on the server by manipulating file path
  input. Successful exploitation may lead to unauthorized access to sensitive
  syste…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-09-11'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:00:03.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69904'
references:
  - url: >-
      https://github.com/pwnzillaa/cves-collection/blob/main/cve-2025-69904/README.md
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00352
epssPercentile: 0.28912
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T16:03:24.464841Z'
ingestedAt: '2026-09-14T00:35:28.535Z'
---

## Overview

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
