CVE-CVE-2026-5027
Severity
HIGH
CVSS Score
8.8
Description
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../')....
PoCs for CVE-CVE-2026-5027
POC-CVE-2026-5027
General
Python
0
rmhowe425
2026-09-02