Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-55668

2 месяца назад

File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-8wc8-hf36-mjh9

около 2 месяцев назад

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-55668

File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the user's scope. This issue is fixed in version 2.63.16.

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-8wc8-hf36-mjh9

File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу