PT-2026-70236 · Rapid7+1 · Velociraptor
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The NewNotebook API fails to properly sanitize parameters, enabling an authenticated user with
NOTEBOOK EDIT permissions to write notebook records outside the organization's data store directory. While the written file must use the .json.db extension, this flaw allows the overwriting of other metadata files, including ACL records and hunts, which can lead to significant data corruption.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velociraptor