PT-2026-55817 · Unknown · Ail Framework
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/U:Clear |
Name of the Vulnerable Software and Affected Versions
AIL Framework versions prior to commit 14c618fce4d1df02358717c48ea903706abecdf2
Description
A path traversal issue exists in the PDF object handling. The
PDF.get filepath() function constructs a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier without verifying if the resolved path remains within the intended PDF FOLDER directory. An authenticated attacker could use relative traversal sequences or absolute path components via a crafted identifier to open files outside the storage directory, potentially leading to the disclosure of sensitive local data, credentials, or application configurations readable by the AIL process.Recommendations
Update AIL Framework to the version containing commit 14c618fce4d1df02358717c48ea903706abecdf2.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ail Framework