LOWVulnerability

CVE-2026-90445

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.

Properties

cve_id
CVE-2026-90445
signal_observed_at
2026-09-21T23:07:07+00:00
published_at
2026-09-11T22:16:46.510
last_modified
2026-09-18T19:40:31.053

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90445 — Ninja Signal Threat Intelligence | Ninja Signal