CVE-2025-62376: pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf
Summary
pwn.college DOJO, an education platform for learning cybersecurity, had a vulnerability in its /workspace endpoint that allowed attackers to access other users' Windows virtual machines (VMs, which are simulated computers) without permission. The flaw occurred because the system retrieved user information from a URL parameter without checking if the requester had admin privileges, and it didn't verify passwords before granting access to a user's desktop, potentially allowing attackers to view and modify files on both Windows and Linux systems.
Solution / Mitigation
This issue has been patched in commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef. No known workarounds exist.
Vulnerability Details
EPSS: 0.1%
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-62376
First tracked: February 15, 2026 at 08:53 PM
Classified by LLM (prompt v3) · confidence: 95%