CRITICALVulnerability

CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

Properties

severity
CRITICAL
score
9.1
cve_id
CVE-2026-66145
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-08-11T20:18:37.717
last_modified
2026-08-28T18:58:27.140

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-66145 — Ninja Signal Threat Intelligence | Ninja Signal