CVE-2026-24815

Severity CVSS v4.0:
CRITICAL
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
27/01/2026
Last modified:
27/01/2026

Description

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java.<br /> <br /> This issue affects tis: before v4.3.0.

References to Advisories, Solutions, and Tools