PT-2026-82322 · Unknown · Yx-Image-Recognition
CVE-2026-75333
·
Published
2026-08-26
·
Updated
2026-08-31
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
yx-image-recognition version 1.0
Description
The software is subject to Path Traversal, a condition where an attacker can access files and directories outside the intended folder. This occurs because the parameters
dir and filePath are passed directly to the new File() function for file system operations without undergoing path sanitization or whitelist validation.Recommendations
Update yx-image-recognition version 1.0 to a version that implements proper path sanitization and whitelist validation for the
dir and filePath parameters.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yx-Image-Recognition