Unknown · Ruoyi-Vue-Pro · CVE-2026-97323
**Name of the Vulnerable Software and Affected Versions**
ruoyi-vue-pro versions prior to 2026.09
**Description**
A path traversal issue exists in the File Upload component. This occurs within the `getOriginalFilename()` function located in the `yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java` file. A remote attacker can manipulate the input to access or traverse directories outside the intended folder.
**Recommendations**
Update ruoyi-vue-pro to a version later than 2026.08.
As a temporary workaround, restrict the use of the `getOriginalFilename()` function until a patch is applied.