PT-2026-56675 · Dspace+2 · Dspace+1
CVE-2026-49830
·
Published
2026-07-08
·
Updated
2026-09-02
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DSpace versions prior to 7.6.7
DSpace versions 8.0 through 8.3
DSpace versions 9.0 through 9.2
Description
When ingesting an aggregated ORE resource by URI using the OAI-ORE Harvester, the ORE Ingestion Crosswalk fails to validate the URI scheme. This allows an attacker with DSpace collection administrator privileges to perform local file inclusion by providing malicious paths, such as
file:///etc/passwd. A remote OAI endpoint configured as a harvest source can supply malicious ORE XML, resulting in local files from the DSpace server being ingested as a bitstream.Recommendations
Update DSpace to version 7.6.7, 8.4, 9.3, or 10.0.
As a temporary workaround, disable the ORE ingestion crosswalk in
dspace.cfg by removing or commenting out the org.dspace.content.crosswalk.OREIngestionCrosswalk plugin.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dspace
Org.Dspace:Dspace-Api