PT-2026-55817 · Unknown · Ail Framework

·

CVE-2026-59510

·

Published

2026-07-05

·

Updated

2026-07-06

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/U:Clear
Name of the Vulnerable Software and Affected Versions AIL Framework versions prior to commit 14c618fce4d1df02358717c48ea903706abecdf2
Description A path traversal issue exists in the PDF object handling. The PDF.get filepath() function constructs a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier without verifying if the resolved path remains within the intended PDF FOLDER directory. An authenticated attacker could use relative traversal sequences or absolute path components via a crafted identifier to open files outside the storage directory, potentially leading to the disclosure of sensitive local data, credentials, or application configurations readable by the AIL process.
Recommendations Update AIL Framework to the version containing commit 14c618fce4d1df02358717c48ea903706abecdf2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59510

Affected Products

Ail Framework