All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-66145
CRITICALpublished 2026-08-11 20:18 UTC · 1 day ago · modified 2026-08-12 15:18 UTC
9.1
CVSS / 10
// description
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
// weaknesses (CWE)
- CWE-94