CVE-2026-92533High· 7.1▾ TwilightPath traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to ac…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could allow the attacker to read system files accessible to the account used by the application.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92532High· 7.5Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality
CVE-2026-92531High· 7.5Operating system command injection vulnerability in the SVN integration component of BugTracker.NET
CVE-2026-41082High· 7.3In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-105314High· 7.5Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call
CVE-2026-104994Low· 2.5Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root
CVE-2026-103088High· 7.5Handlebars.java before 4.5.5 allows directory traversal