8.2

CVE-2026-40163

Exploit

Saltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory read

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write a changes.json file with attacker-controlled JSON content anywhere on the server filesystem. The GET /sync/upload_finished endpoint allows an unauthenticated attacker to list arbitrary directory contents and read specific JSON files. This vulnerability is fixed in 1.4.5, 1.5.5, and 1.6.0-beta.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SaltcornSaltcorn Version < 1.4.5
SaltcornSaltcorn Version >= 1.5.0 < 1.5.5
SaltcornSaltcorn Version1.6.0 Updatealpha0
SaltcornSaltcorn Version1.6.0 Updatealpha1
SaltcornSaltcorn Version1.6.0 Updatealpha10
SaltcornSaltcorn Version1.6.0 Updatealpha11
SaltcornSaltcorn Version1.6.0 Updatealpha12
SaltcornSaltcorn Version1.6.0 Updatealpha13
SaltcornSaltcorn Version1.6.0 Updatealpha14
SaltcornSaltcorn Version1.6.0 Updatealpha15
SaltcornSaltcorn Version1.6.0 Updatealpha16
SaltcornSaltcorn Version1.6.0 Updatealpha17
SaltcornSaltcorn Version1.6.0 Updatealpha2
SaltcornSaltcorn Version1.6.0 Updatealpha3
SaltcornSaltcorn Version1.6.0 Updatealpha4
SaltcornSaltcorn Version1.6.0 Updatealpha5
SaltcornSaltcorn Version1.6.0 Updatealpha6
SaltcornSaltcorn Version1.6.0 Updatealpha7
SaltcornSaltcorn Version1.6.0 Updatealpha8
SaltcornSaltcorn Version1.6.0 Updatealpha9
SaltcornSaltcorn Version1.6.0 Updatebeta1
SaltcornSaltcorn Version1.6.0 Updatebeta2
SaltcornSaltcorn Version1.6.0 Updatebeta3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.249
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://github.com/saltcorn/saltcorn/security/advisories/GHSA-32pv-mpqg-h292
Vendor Advisory
Exploit
Mitigation