GHSA-9cp7-j3f8-p5jx
### Impact The `cloudstore.file.upload` action in `server/actions/action_cloudstore_file_upload.go` writes user-supplied filenames directly to disk without proper validation. This allows unauthenticated attackers to perform path traversal and zip slip attacks, leading to arbitrary file write and potential remote code execution. **CVSS Score:** 10.0 Critical **CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H **CWE:** CWE-22 (Path Traversal) ### Patches Upgrade to a patched version once released. The vulnerability affects all versions <= v0.11.3 (latest). ### Workarounds Restrict access to the cloudstore.file.upload action through authentication and authorization controls until a patch is available.
Properties
- ghsa_id
- GHSA-9cp7-j3f8-p5jx
- severity
- critical
- summary
- Daptin has Unauthenticated Path Traversal and Zip Slip
- cvss_score
- 10
- cve_id
- GHSA-9cp7-j3f8-p5jx
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-04-10T22:11:04Z
- source_url
- https://github.com/advisories/GHSA-9cp7-j3f8-p5jx
- ghsa_updated
- 2026-04-10T22:11:07Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph