PT-2026-50867 · Unknown · Ail Framework
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIL framework (affected versions not specified)
Description
A path traversal issue exists in the '/objects/item/diff' endpoint. The endpoint accepts item identifiers via the
s1 and s2 query parameters and attempts to retrieve and compare item contents without verifying that the referenced items are valid AIL objects. An authenticated user can use path traversal sequences in these parameters to read gzip-compressed files accessible to the AIL process, potentially leading to the unauthorized disclosure of local file contents compatible with the expected gzip format.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ail Framework