What is CVE-2026-48499?
In Activepieces, an unsanitized path segment in the Code piece sandbox allows authenticated flow authors to access read-write cached flow and code files from other tenants on the same worker, potentially exposing embedded data. Users should upgrade to version 0.84.0 to mitigate this issue.
Azərbaycanca: Activepieces platformasında kod sandboxunda sanitizə olunmamış yol seqmenti səbəbindən autentifikasiya olunmuş axın müəllifi eyni işçi üzərindəki digər kirayəçilərə məxsus keşlənmiş axın və kod fayllarına oxuma-yazma girişi əldə edə, daxili məlumatları ifşa edə bilər. Bütün istifadəçilər 0.84.0 versiyasına yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What type of data can be exposed due to CVE-2026-48499 in Activepieces?
This vulnerability allows authenticated flow authors to gain read-write access to cached flow and code files from other tenants on the same worker, potentially exposing embedded data.
What should Activepieces users do to mitigate CVE-2026-48499?
Users should upgrade Activepieces to version 0.84.0 to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.