PT-2026-56676 · Dspace+2 · Dspace+1
CVE-2026-49831
·
Published
2026-07-08
·
Updated
2026-09-02
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
DSpace versions prior to 7.6.7
DSpace versions 8.0 through 8.3
DSpace versions 9.0 through 9.2
Description
A path traversal issue exists in the
curate script within the Curation Task feature. The reporter -r parameter, used to stream results and status of operations, does not restrict the output to a specific base path. This allows an attacker with Collection, Community, or Site Administrator credentials to specify an output path writable by the DSpace user (typically 'tomcat'), potentially leading to the overwriting of configuration files or the placement of files in unexpected locations, such as the static resources folder of the Spring boot webapp. Such actions could result in a denial of service attack.Recommendations
Update DSpace to version 7.6.7, 8.4, 9.3, or 10.0.
As a temporary workaround, disable all Curation Tasks by commenting out every
CurationTask plugin in the curate.cfg file.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dspace
Org.Dspace:Dspace-Api