Tag

#Path Traversal

newsHIGH 7.1

Grav CMS Path Traversal Vulnerability in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

A path traversal vulnerability in Grav CMS's MediaUploadTrait::deleteFile() allows authenticated users with media management permissions to delete arbitrary files on the server. This vulnerability has a CVSS score of 7.1 and is classified as CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').

1 source
articleHIGH 8.8

Critical Path Traversal Vulnerability in Weights & Biases wandb: CVE-2026-91771

A critical path traversal vulnerability (CVE-2026-91771) has been discovered in Weights & Biases wandb versions before 0.29.0. This vulnerability allows attackers controlling the backend to supply malicious file names with directory traversal sequences, potentially leading to code execution. The vulnerability has a CVSS score of 8.8 and is considered high severity. Immediate patching to version 0.29.0 or later is recommended.

1 source
articleHIGH 8.1

CVE-2026-19991: Arbitrary File Deletion Vulnerability in UsersWP Plugin for WordPress

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70. This vulnerability allows authenticated attackers with Subscriber-level access and above to delete arbitrary files on the affected site's server, including critical files like wp-config.php. The vulnerability has a CVSS score of 8.1, indicating a high severity. Immediate patching is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.8

Critical Vulnerability in SigmaForms Pro – AI Generated Forms Plugin for WordPress: Arbitrary File Deletion

A critical vulnerability, CVE-2026-78657, with a CVSS score of 9.8, was discovered in the SigmaForms Pro – AI Generated Forms plugin for WordPress. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validation in the delete_submission_files function. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted. The vulnerability affects all versions up to and including 1.4.11 of the plugin.

1 source
articleHIGH 8.8

Critical Vulnerability in Eclipse Theia: Path Traversal and Code Execution Risk

A critical vulnerability, CVE-2026-82217, with a CVSS score of 8.8, was discovered in Eclipse Theia versions 1.73.0 to 1.74.99. This vulnerability allows attackers to write or delete files outside the workspace with the privileges of the Theia backend OS user, potentially leading to code execution. The vulnerability is caused by a lack of workspace-containment checks in the AI 'Agent Mode' file-change tools. Immediate patching is recommended to prevent potential exploitation.

1 source
newsHIGH 8.8

Critical Vulnerability in Pake: Path Traversal and Code Execution

A critical vulnerability (CVE-2026-82635) with a CVSS score of 8.8 affects Pake versions before 3.13.1, allowing attackers to execute code on user accounts by overwriting user-writable files. All desktop apps generated from an affected Pake tree are vulnerable. Immediate action is required to update to version 3.13.1 or later.

1 source
newsHIGH 7.5

CVE-2026-62388: NLTK Insecure Default Configuration in pathsec.py Allows Path Traversal and Pickle Deserialization Bypass

A vulnerability in NLTK versions before 3.10.0 allows attackers to bypass path traversal and pickle deserialization protections due to insecure default configuration. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected users should update NLTK to version 3.10.0 or later.

1 source
articleCRITICAL 9.9

Critical Path Traversal Vulnerability in Incus: CVE-2026-48753

A critical vulnerability (CVE-2026-48753) with a CVSS score of 9.9 affects Incus, a system container and virtual machine manager. The vulnerability allows for path traversal and creation of arbitrary files on the host, potentially leading to arbitrary command execution. The issue is fixed in version 7.1.0. Organizations using Incus prior to version 7.1.0 are advised to upgrade immediately.

1 source
blogHIGH 8.7

Understanding and Defending Against Path Traversal in logto-tunnel

This educational analysis covers CVE-2026-63188, a path traversal vulnerability in the logto-tunnel package. The vulnerability allows an attacker to read files outside the intended directory by exploiting the `--experience-path` option. We will delve into the root cause, attack surface, exploitation mechanics, and provide defensive strategies.

1 source
newsHIGH 8.8

Copier Trust-Prefix Bypass via Path Traversal (CVE-2026-53951)

A vulnerability in Copier (CVE-2026-53951) allows an attacker to bypass the trust prefix check via path traversal, leading to arbitrary command execution. Affected versions are Copier >= 9.5.0 and <= 9.15.1. Users should update to a patched version to mitigate this high-severity vulnerability.

1 source
articleHIGH 8.1

Arbitrary File Write Vulnerability in extract-zip: CVE-2026-19693

A high-severity vulnerability (CVE-2026-19693, CVSS 8.1) exists in the extract-zip package, allowing for arbitrary file writes outside the intended destination directory. This issue, classified as CWE-22 and CWE-59, affects versions up to 2.0.1 and has a significant impact on data integrity and availability. Immediate patching is recommended to prevent potential exploitation.

1 source
blogHIGH 7.8

Understanding Path Traversal in SeaweedFS: Exploitation and Defense

This educational analysis delves into a critical path traversal vulnerability in SeaweedFS, affecting its S3 and Iceberg REST gateways. The flaw allows for cross-bucket access, potentially leading to unauthorized data reads and writes. We will explore the root cause, attack scenarios, and provide guidance on mitigations and defenses.

1 source
articleCRITICAL 9.0

CVE-2026-54910: FileBrowser Quantum Path Traversal Vulnerability Allows Authenticated Users to Read Arbitrary Files

A critical path traversal vulnerability, CVE-2026-54910, has been discovered in FileBrowser Quantum's subtitle handler. This flaw allows any authenticated user to read arbitrary files on the host filesystem, including sensitive files such as /etc/passwd, SSH keys, and database credentials. The vulnerability is caused by the lack of sanitization in the `path` and `name` parameters used in filesystem operations. Immediate patching is recommended to prevent potential exploitation.

1 source
blogCRITICAL 9.8

Understanding and Defending Against CVE-2026-65687: A Critical Path Traversal Vulnerability in Bold Reports Standalone Report Designer

CVE-2026-65687 is a critical vulnerability in Bold Reports Standalone Report Designer before version 14.1.12. This vulnerability allows unauthenticated attackers to read arbitrary files from the server filesystem by exploiting a missing filepath validation in the SVG processing feature. With a CVSS score of 9.8, this vulnerability poses a significant risk as it can lead to full unauthorized access to the application. Understanding the mechanics of this vulnerability and implementing defensive measures is crucial for protecting against potential attacks.

1 source
articleCRITICAL 9.0

Critical Path Traversal Vulnerability in Red Hat Ansible Automation Platform and Satellite (CVE-2026-12701)

A high-severity path traversal vulnerability (CVE-2026-12701, CVSS 9) was discovered in pulpcore, affecting Red Hat Ansible Automation Platform and Satellite. An authenticated administrator can exploit this flaw to write arbitrary files to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation. Immediate patching is recommended.

1 source
newsMEDIUM 6.5

CVE-2026-12898: Unauthenticated Log File Creation/Append Vulnerability in All-in-One WP Migration and Backup Plugin

A vulnerability in the All-in-One WP Migration and Backup WordPress plugin before version 7.106 allows unauthenticated attackers to create or append log files in arbitrary locations. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Affected versions are prior to 7.106.

1 source
newsCRITICAL 9.6

Critical Path Traversal Vulnerability in JetBrains IntelliJ IDEA

A critical vulnerability (CVE-2026-59792) with a CVSS score of 9.6 was discovered in JetBrains IntelliJ IDEA, allowing for code execution via path traversal in project workspace ID handling. Users of IntelliJ IDEA versions before 2026.1.4 and 2026.2 are affected. Immediate action is required to update to a patched version.

1 source
blogHIGH 8.4

Understanding and Defending Against CVE-2026-58302: A LinuxCNC Privilege Escalation Vulnerability

CVE-2026-58302 is a privilege escalation vulnerability in LinuxCNC before version 2.9.9, allowing unprivileged local users to escalate privileges to root. This vulnerability is caused by insufficient validation of user-supplied module names, leading to path traversal and arbitrary shared library loading. The vulnerability has a CVSS score of 8.4, indicating high severity.

1 source
newsHIGH 8.8

CVE-2026-40521: Path Traversal Vulnerability in FrontAccounting

A path traversal vulnerability in FrontAccounting before 2.4.20 allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences. This vulnerability has a CVSS score of 8.8 and is considered high severity.

1 source
articleHIGH 8.8

Critical Vulnerability in Jenkins External Workspace Manager Plugin Allows Remote Code Execution

A critical vulnerability, CVE-2026-57296, with a CVSS score of 8.8, was discovered in the Jenkins External Workspace Manager Plugin. This vulnerability allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, potentially leading to remote code execution. The plugin versions 1.3.2 and earlier are affected. Organizations using this plugin are urged to update to the latest version to mitigate this vulnerability.

1 source
newsHIGH 7.7

CVE-2026-42129: Grafana Loki Datasource Plugin Path Traversal Vulnerability

A path traversal vulnerability in the Grafana Loki datasource plugin allows an authenticated Viewer-role user to access administrative Loki endpoints and extract sensitive backend configuration and internal service information. This vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Affected users should update Grafana OSS to a patched version.

1 source