Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58192

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 8.6
CVSS3: 10
EPSS Низкий

Описание

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value directly into path.join(storageRoot, name) and fs.rimraf() without path sanitization, allowing an unauthenticated remote client to escape the storage root with ../ sequences and recursively delete arbitrary writable files or directories. This issue is fixed in version 1.1.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:appium:appium\/storage-plugin:*:*:*:*:*:node.js:*:*
Версия до 1.1.6 (исключая)

EPSS

Процентиль: 37%
0.00449
Низкий

8.6 High

CVSS3

10 Critical

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 37%
0.00449
Низкий

8.6 High

CVSS3

10 Critical

CVSS3

Дефекты

CWE-22