Home

Description

Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element.

PUBLISHED Reserved 2026-05-19 | Published 2026-05-22 | Updated 2026-05-22 | Assigner 9front




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:P/AU:N/R:A/RE:L/U:Amber

Product status

Default status
unaffected

f04e113279274526a8dae34de373027b68921fbf (git) before d145acc9ef0da47131af6ad94e87264e04870d47
affected

Timeline

2026-05-10:Initial private disclosure
2026-05-11:Fix committed

Credits

Kristo finder

Kristo reporter

Jacob Moody coordinator

Kristo remediation developer

cinap_lenrek remediation developer

References

git.9front.org/...0da47131af6ad94e87264e04870d47/commit.html mitigation

cve.org (CVE-2026-9053)

nvd.nist.gov (CVE-2026-9053)

Download JSON