PT-2026-56676 · Dspace+2 · Dspace+1

CVE-2026-49831

·

Published

2026-07-08

·

Updated

2026-09-02

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions DSpace versions prior to 7.6.7 DSpace versions 8.0 through 8.3 DSpace versions 9.0 through 9.2
Description A path traversal issue exists in the curate script within the Curation Task feature. The reporter -r parameter, used to stream results and status of operations, does not restrict the output to a specific base path. This allows an attacker with Collection, Community, or Site Administrator credentials to specify an output path writable by the DSpace user (typically 'tomcat'), potentially leading to the overwriting of configuration files or the placement of files in unexpected locations, such as the static resources folder of the Spring boot webapp. Such actions could result in a denial of service attack.
Recommendations Update DSpace to version 7.6.7, 8.4, 9.3, or 10.0. As a temporary workaround, disable all Curation Tasks by commenting out every CurationTask plugin in the curate.cfg file.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49831
GHSA-V66X-68F2-PXF5

Affected Products

Dspace
Org.Dspace:Dspace-Api