Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24741

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the POST /delete endpoint uses a user-controlled filename value to construct a filesystem path and deletes it via unlink without sufficient validation. By supplying path traversal sequences (e.g., ../), an attacker can delete arbitrary files outside the intended uploads directory, limited only by the permissions of the server process. Version 0.17.0 fixes the issue.

EPSS

Процентиль: 24%
0.00083
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 24%
0.00083
Низкий

8.1 High

CVSS3

Дефекты

CWE-22