What is CVE-2026-19326?
This is a path traversal vulnerability found in Jevon-Zhong Ai-doctor version 0.0.1. It exists in the `deleteImage` function within the file `ai-doctor-server/src/filemanagement/filemanagement.service.ts`, where improper handling of the `imagePath` argument allows remote exploitation. Users should immediately update the software or restrict file path operations.
Azərbaycanca: Bu, Jevon-Zhong Ai-doctor 0.0.1 proqramında aşkar edilmiş path traversal zəifliyidir. `ai-doctor-server/src/filemanagement/filemanagement.service.ts` faylındakı `deleteImage` funksiyasında `imagePath` arqumentinin düzgün yoxlanılmaması səbəbindən uzaqdan hücum mümkündür. İstifadəçilər dərhal proqramı yeniləməli və ya fayl yollarını məhdudlaşdırmalıdırlar.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which software was CVE-2026-19326 discovered?
This path traversal vulnerability was discovered in version 0.0.1 of the Jevon-Zhong Ai-doctor application.
Which function contains the CVE-2026-19326 vulnerability?
The vulnerability exists in the `deleteImage` function within the file `ai-doctor-server/src/filemanagement/filemanagement.service.ts` due to improper handling of the `imagePath` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.