PT-2026-51312 · Unknown · Ail Framework

·

CVE-2026-56448

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:P
Name of the Vulnerable Software and Affected Versions AIL Framework versions prior to commit 0041456af25da0cdea1c1c4624e46baff2731d8f
Description A path traversal issue allows an authenticated user to supply crafted object identifiers through the investigation workflow, causing file paths to resolve outside the intended image, favicon, or screenshot storage directories. This occurs because user-controlled path components are joined with application storage paths without verifying that the resolved path remains within the expected directory. Consequently, an attacker can download and read arbitrary files accessible to the AIL process via the affected download functionality, which may include these files in a generated archive.
Recommendations Update to the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56448

Affected Products

Ail Framework