criticalCVSS 10Vulnerability

GHSA-9cp7-j3f8-p5jx

### Impact The `cloudstore.file.upload` action in `server/actions/action_cloudstore_file_upload.go` writes user-supplied filenames directly to disk without proper validation. This allows unauthenticated attackers to perform path traversal and zip slip attacks, leading to arbitrary file write and potential remote code execution. **CVSS Score:** 10.0 Critical **CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H **CWE:** CWE-22 (Path Traversal) ### Patches Upgrade to a patched version once released. The vulnerability affects all versions <= v0.11.3 (latest). ### Workarounds Restrict access to the cloudstore.file.upload action through authentication and authorization controls until a patch is available.

Properties

ghsa_id
GHSA-9cp7-j3f8-p5jx
severity
critical
summary
Daptin has Unauthenticated Path Traversal and Zip Slip
cvss_score
10
cve_id
GHSA-9cp7-j3f8-p5jx
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-04-10T22:11:04Z
source_url
https://github.com/advisories/GHSA-9cp7-j3f8-p5jx
ghsa_updated
2026-04-10T22:11:07Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]go/github.com/daptin/daptin

AFFECTS (1)

[Software]go/github.com/daptin/daptin

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9cp7-j3f8-p5jx (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal