PT-2026-61627 · Unknown · Datacycle-Core
CVE-2026-32820
·
Published
2026-07-20
·
Updated
2026-07-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dataCycle-CORE versions prior to 26.06.08
Description
The documentation and static markdown renderer in the core processing and framework rules module accepts attacker-controlled path segments. Because these segments are only processed by the Rails HTML sanitizer, which fails to remove directory traversal sequences, an unauthenticated attacker can access and render arbitrary
.md files from the application root or engine root by traversing outside the intended docs or static directories.Recommendations
Update dataCycle-CORE to version 26.06.08.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datacycle-Core