{"id":"CVE-2025-61666","summary":"Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File","details":"Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1-  6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to leakage of passwords or any file on the file system including the Traccar configuration file. Versions 5.8 - 6.0 are only vulnerable if \u003centry key='web.override'\u003e./override\u003c/entry\u003e is set in the configuration file. Versions 6.1 - 6.8.1 are vulnerable by default as the web override is enabled by default. The vulnerable code is removed in version 6.9.0.","aliases":["GHSA-hprc-rph8-fj87"],"modified":"2026-08-12T03:51:29.495521616Z","published":"2025-10-02T21:15:47.047Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61666.json"},"references":[{"type":"WEB","url":"https://github.com/traccar/traccar/blob/v6.8.1/src/main/java/org/traccar/web/DefaultOverrideServlet.java"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61666.json"},{"type":"ADVISORY","url":"https://github.com/traccar/traccar/security/advisories/GHSA-hprc-rph8-fj87"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61666"},{"type":"ARTICLE","url":"https://projectblack.io/blog/jetty-addpath-lfi"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/traccar/traccar","events":[{"introduced":"a24d7d5d7a61946b45ed5d344fee0a0e27bd3144"},{"fixed":"001bccee54cbd516b5369c73cc338319d30122fc"}],"database_specific":{"extracted_events":[{"introduced":"5.8"},{"fixed":"6.9.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v6.8.1","v6.8.0","v6.7.3","v6.7.2","v6.7.1","v6.7.0","v6.6","v6.5","v6.4","v6.3","v6.2","v6.1","v6.0","v5.12","v5.11","v5.10","v5.9","v5.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61666.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N"}]}