Home

Description

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

PUBLISHED Reserved 2026-04-21 | Published 2026-05-11 | Updated 2026-05-11 | Assigner certcc

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Any version
affected

References

www.kb.cert.org/vuls/id/937808

kb.cert.org/vuls/id/937808

cve.org (CVE-2026-6815)

nvd.nist.gov (CVE-2026-6815)

Download JSON