CVE-2025-69618

An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information.
References
Link Resource
http://coto.com Broken Link
https://coto.world/ Product
https://github.com/Secsys-FDU/AF_CVEs/issues/9 Exploit Third Party Advisory
https://secsys.fudan.edu.cn/ Not Applicable
Configurations

Configuration 1 (hide)

cpe:2.3:a:coto.world:coto:11.4.0:*:*:*:*:android:*:*

History

No history.

Information

Published : 2026-02-04 15:16

Updated : 2026-03-13 19:53


NVD link : CVE-2025-69618

Mitre link : CVE-2025-69618

CVE.ORG link : CVE-2025-69618


JSON object : View

Products Affected

coto.world

  • coto
CWE
NVD-CWE-noinfo CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')