What is CVE-2026-72569?
A path traversal vulnerability in cube-root/directory-serve through version 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the served directory. This occurs when the application is run with the --delete option. Users should update immediately or disable the --delete flag.
Azərbaycanca: cube-root/directory-serve komponentinin 1.3.7-ə qədər versiyalarında path traversal zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış uzaqdan hücumçuya `--delete` seçimi aktiv olduqda serverin təqdim etdiyi qovluqdan kənarda ixtiyari faylları silməyə imkan verir. Təcili olaraq komponenti yeniləmək və ya `--delete` seçimini deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What component is affected by CVE-2026-72569?
The vulnerability affects the cube-root/directory-serve component through version 1.3.7.
Does CVE-2026-72569 require authentication to exploit?
No, the vulnerability allows an unauthenticated remote attacker to delete arbitrary files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.