Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62843

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "", "/"), which turns a POSIX filename such as ....\evil.sh into the archive entry ../../evil.sh, allowing a user with upload permission to plant a backslash-named file that escapes the extraction directory when another user downloads and extracts the generated zip or tar archive. This issue is fixed in version 2.63.17.

EPSS

Процентиль: 17%
0.00259
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
github
22 дня назад

File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)

EPSS

Процентиль: 17%
0.00259
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22