CVE-2026-105174

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,1
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,4
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: low
MEDIUM 5,5
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: none
Integrity: partial
Availability: partial

Description

AI Translation Available

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. The manipulation of the argument project_name leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The identifier of the patch is 6e481078cfba6388a67ca2d9792288405019ba3e. Applying a patch is the recommended action to fix this issue.

22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Files Or Directories Read Files Or Directories Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: AI/ML
View CWE Details
https://github.com/Gerapy/Gerapy/
https://github.com/Gerapy/Gerapy/commit/6e481078cfba6388a67ca2d9792288405019ba3e
https://github.com/Gerapy/Gerapy/issues/317
https://github.com/Gerapy/Gerapy/pull/319
https://vuldb.com/cve/CVE-2026-105174
https://vuldb.com/submit/970586
https://vuldb.com/vuln/413406
https://vuldb.com/vuln/413406/cti