PT-2026-82488 · Blackms · Aistack

·

CVE-2026-81560

·

Published

2026-08-27

·

Updated

2026-08-29

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions blackms aistack versions prior to 1.6.2
Description A path traversal issue exists in the Static File Handler component within the file src/web/server.ts. A remote attacker can manipulate the req.url argument to access files and directories outside the intended folder. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81560

Affected Products

Aistack