7.2
/ 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
Basic Information
ID
CVE-2026-41951
Source
jpcert
Published
May 11, 2026 at 09:32
Affected Product
Vendor
GROWI, Inc.
Product
GROWI
Version
v7.5.0 and earlier
Affected Versions
GROWI, Inc. GROWI v7.5.0 and earlier