---
id: CVE-2026-95140
title: >-
  kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability
  in FileController.java
summary: >-
  kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability
  in FileController.java. The fileUpload, createFolder and existsFile endpoints
  accept a "path" parameter that is concatenated into the upload base path
  without …
severity: none
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T17:17:28.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95140'
references:
  - url: 'https://github.com/sg-summer/cve/issues/4'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T17:09:22.190Z'
---

## Overview

kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints accept a "path" parameter that is concatenated into the upload base path without validation, allowing unauthenticated attackers to create arbitrary directories and write arbitrary files outside the intended fileDir root via a crafted multipart request

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
