← All CVEs

CVE-2026-66145

critical · 9.1

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

9.1
CVSS
0.7%
EPSS (exploit prob.)
50th
EPSS percentile
2026-08-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-94

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-66145