CVE-2026-49831Medium· 5.5▾ SunlitDSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.dspace:dspace-api <= 7.6.6org.dspace:dspace-api >= 8.0-rc1, <= 8.3org.dspace:dspace-api >= 9.0-rc1, <= 9.2org.dspace:dspace-api = 10-rc1Patched in:
org.dspace:dspace-api 7.6.7org.dspace:dspace-api 8.4org.dspace:dspace-api 9.3org.dspace:dspace-api 10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49833Medium· 5.5DSpace open source software is a repository application which provides durable access to digital resources
CVE-2026-49832High· 8.0DSpace open source software is a repository application which provides durable access to digital resources
CVE-2026-49830Medium· 4.4DSpace open source software is a repository application which provides durable access to digital resources
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4
CVE-2023-7249Critical· 9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
CVE-2020-3365Medium· 4.3A vulnerability in the directory permissions of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a directory traversal attack on a limited set of restricted directories