yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in yx-image-recognition v1.0 | |
| Weaknesses | CWE-22 |
Wed, 26 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-26T21:40:12.714Z
Reserved: 2026-08-17T00:00:00.000Z
Link: CVE-2026-75333
No data.
Status : Received
Published: 2026-08-26T22:16:29.327
Modified: 2026-08-26T22:16:29.327
Link: CVE-2026-75333
No data.
OpenCVE Enrichment
Updated: 2026-08-26T23:30:12Z