OpenSave vulnerabilities
CVEs whose affected-version data names the OpenSave package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-103398High· 8.1OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured save locations to read and write files through manifest…
▾ TwilightLiquid-co · OpenSavevia NVD
CVE-2026-103397Medium· 5.6OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From field. Attackers who know the room code can join, read p…
▾ SunlitLiquid-co · OpenSavevia NVD