PT-2026-51312 · Unknown · Ail Framework
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/S:P |
Name of the Vulnerable Software and Affected Versions
AIL Framework versions prior to commit 0041456af25da0cdea1c1c4624e46baff2731d8f
Description
A path traversal issue allows an authenticated user to supply crafted object identifiers through the investigation workflow, causing file paths to resolve outside the intended image, favicon, or screenshot storage directories. This occurs because user-controlled path components are joined with application storage paths without verifying that the resolved path remains within the expected directory. Consequently, an attacker can download and read arbitrary files accessible to the AIL process via the affected download functionality, which may include these files in a generated archive.
Recommendations
Update to the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ail Framework