7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components
Basic Information
ID
CVE-2026-38361
Source
mitre
Published
May 8, 2026 at 00:00
Modified
May 8, 2026 at 18:27
Affected Product
Vendor
n/a
Product
n/a
Version
n/a
Affected Versions
n/a n/a n/a
CWE Classification
References
- github.com /fohrloop/dash-uploader
- pypi.org /project/dash-uploader/
- github.com /fohrloop/dash-uploader/blob/stable/dash_uploader/httprequesthandler.py
- github.com /fohrloop/dash-uploader/issues/153
- pypistats.org /packages/dash-uploader
- libraries.io /pypi/dash-uploader
- pepy.tech /project/dash-uploader
- docs.python.org /3/library/functions.html
- github.com /a1ohadance/CVE-2026-38361