PT-2026-60527 · Manyfold · Manyfold

CVE-2026-46336

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Manyfold versions 0.96.0 through 0.139.0
Description Authenticated users can rename uploaded files using path traversal sequences. This occurs because the app/models/model file.rb file utilizes a user-controlled filename within the File.join(model.path, filename) function without sufficient sanitization. Path traversal is a technique used to access files and directories that are stored outside the web root folder. This flaw allows files to be moved or written outside the configured library directory.
Recommendations Update Manyfold to version 0.140.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46336
GHSA-J5F9-R7WF-HV37

Affected Products

Manyfold