What is CVE-2026-18903?
This CVE describes a path traversal vulnerability in yeqifu warehouse's FileController.java file due to improper sanitization of the 'path' argument. This could allow a remote attacker to read arbitrary files on the system. Updating affected versions or implementing strict input validation is recommended.
Azərbaycanca: Bu CVE, yeqifu deposunda `FileController.java` faylında `path` arqumentinin düzgün yoxlanılmaması nəticəsində path traversal zəifliyini təsvir edir. Bu, uzaqdan hücum edənə sistemdəki faylları oxumağa imkan verə bilər. Təsirlənən versiyaları yeniləmək və ya giriş validasiyasını gücləndirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which file is affected by CVE-2026-18903?
The vulnerability was found in the `FileController.java` file within the yeqifu repository.
What causes the path traversal vulnerability in CVE-2026-18903?
The vulnerability is caused by improper sanitization of the 'path' argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.