9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components
AI Analysis
Directory Traversal vulnerability allowing remote code execution
Basic Information
ID
CVE-2026-38360
Source
mitre
Published
May 8, 2026 at 00:00
Modified
May 8, 2026 at 18:04
Affected Product
Vendor
fohrloop
Product
dash-uploader
Version
v.0.1.0-v.0.7.0a2
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
fohrloop
Product
dash-uploader
Version
v.0.1.0-v.0.7.0a2
References
- github.com /fohrloop/dash-uploader
- pypi.org /project/dash-uploader/
- github.com /fohrloop/dash-uploader/blob/stable/dash_uploader/httprequesthandler.py
- github.com /fohrloop/dash-uploader/blob/dev/dash_uploader/httprequesthandler.py
- github.com /fohrloop/dash-uploader/issues/153
- github.com /a1ohadance/CVE-2026-38360