← Back
Web Application
CVE-2026-86538 high CVSS 7.5

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply dir...

Summary

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensit...

AI summary openai / gpt-4o

knowsのバージョン0.30.0未満には、/api/templates/previewエンドポイントにおいてディレクトリ・トラバーサルの脆弱性が存在します。この脆弱性を利用すると、認証されていない攻撃者がテンプレートファイルパラメータを操作し、任意のファイルを読むことが可能です。
❓ What is the problem
path traversalの脆弱性
📍 Affected scope
/api/templates/preview エンドポイントで影響
🔥 Severity
認証されていない攻撃者が機密ファイルを読むことが可能であり、高リスクとされる
🔧 How to fix
バージョン0.30.0以上にアップデートする
🛡️ Workaround
該当エンドポイントへのアクセスを制限することによる防御策の検討
🔍 Detection
テンプレートファイルパラメータに不正なディレクトリ・トラバーサルシーケンスがないかログを確認

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →