Loading
The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.
Use CWE-125, Thinkphp vendor hub and Thinkphp product page to widen CVE-2025-63889 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-63888, CVE-2025-50707 and CVE-2025-50706 for nearby disclosures in the same product family.