Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91144

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

EPSS

Процентиль: 31%
0.00371
Низкий

7.5 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.5
github
4 дня назад

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the intended access restrictions.

EPSS

Процентиль: 31%
0.00371
Низкий

7.5 High

CVSS3

Дефекты

CWE-639