PT-2026-99146 · Laranode · Laranode

·

CVE-2026-100520

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Laranode versions prior to 1.2.1
Description Authenticated users can perform a path traversal attack via the 'POST /filemanager/upload-file' endpoint. By providing directory traversal sequences in the path parameter, an attacker can write arbitrary files, such as PHP files, outside their designated home directory and into the web roots of other tenants, leading to remote code execution within those tenants' contexts.
Recommendations Update Laranode to version 1.2.1 or later. As a temporary mitigation, restrict access to the 'POST /filemanager/upload-file' endpoint or avoid using the path parameter until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100520
GHSA-34H2-2696-VFVR

Affected Products

Laranode