Unknown · Ail Framework · CVE-2026-56448
**Name of the Vulnerable Software and Affected Versions**
AIL Framework versions prior to commit 0041456af25da0cdea1c1c4624e46baff2731d8f
**Description**
A path traversal issue allows an authenticated user to supply crafted object identifiers through the investigation workflow, causing file paths to resolve outside the intended image, favicon, or screenshot storage directories. This occurs because user-controlled path components are joined with application storage paths without verifying that the resolved path remains within the expected directory. Consequently, an attacker can download and read arbitrary files accessible to the AIL process via the affected download functionality, which may include these files in a generated archive.
**Recommendations**
Update to the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f.