CVE-2026-5027
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
- Published Mar 27, 2026
- CVSS 8.8 high
- 4.8% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
Affected software
In the news
- The vulnerabilities AI finds are the ones attackers want Help Net Security ·
- Vulnerability Discovery and Exploitation Trends in the AI Era Google Threat Intelligence ·
- Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack VulnCheck Blog ·
- VulnCheck State of Exploitation 1H-2026 VulnCheck Blog ·