PT-2026-70911 · Unknown · Kkfileview

CVE-2026-73243

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions kkFileView versions prior to 5.0.1
Description The unauthenticated GET '/addTask' endpoint is omitted from TrustHostFilter and TrustDirFilter. This allows FileConvertQueueTask to fetch a URL selected by an attacker after the getFileAttribute() function in FileHandlerService uses the fullfilename parameter to force an OFFICE, COMPRESS, or CAD type.
Recommendations Update to version 5.0.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73243
GHSA-GWWJ-52HV-6G2M

Affected Products

Kkfileview