Path-traversal

7 posts tagged with “Path-traversal”

Self-managed GitLab: unauth commits API file read hits CISA KEV
cvegitlabpath-traversal

Self-managed GitLab: unauth commits API file read hits CISA KEV

How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

Sep 11, 2026
Read
CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)
cveteamviewercommand-injection

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)

How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

Aug 26, 2026
Read
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
cvedb-gptpath-traversal

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

CVE-2026-80104: v0.8.1 contains the original skill-upload fix, but v0.8.2 regresses it; v0.8.2 fixes sibling CVE-2026-73034

Aug 25, 2026
Read
CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal
cvesecurityvulnerability

CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal

How to fix CVE-2026-77068: upgrade n8n to 2.35.5 (floor 2.33.4 / 2.34.1). Member-level MCP schema path traversal RCE in the MAIN process. Not unauthenticated.

Aug 20, 2026
Read
CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir
cvesecurityvulnerability

CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir

How to fix CVE-2026-76832: upgrade agno to 2.3.24 or later (current PyPI 2.9.0). PythonTools path traversal can read, write, or run files outside base_dir.

Aug 19, 2026
Read
BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write
cvesecurityvulnerability

BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write

CVE-2026-74764 is a CVSS 10.0 path traversal in Pandora TAR extraction that lets untrusted archives write outside the analysis directory. v1.12.5 is affected; deploy the upstream fix.

Aug 16, 2026
Read
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
cvesecurityvulnerability

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

Hugging Face Accelerate through 1.14.0 fails to sanitize weight_map entries in sharded checkpoint indexes, allowing arbitrary file reads and denial of service via named pipes. Affects 27M monthly downloads.

Aug 13, 2026
Read