CVE-2026-5027
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
27/03/2026
Last modified:
30/03/2026
Description
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH



