MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normalization or path validation. An attacker who controls a filename returned by a remote cloud storage API can include traversal sequences ../ in the filename to cause downloaded content to be written outside the configured download directory, potentially overwriting arbitrary files including configuration or plugin files reachable by the application process.
History

Mon, 08 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Jxxghp
Jxxghp moviepilot
Vendors & Products Jxxghp
Jxxghp moviepilot

Fri, 05 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating the configured download directory with a filename taken directly from remote cloud API metadata without basename normalization or path validation. An attacker who controls a filename returned by a remote cloud storage API can include traversal sequences ../ in the filename to cause downloaded content to be written outside the configured download directory, potentially overwriting arbitrary files including configuration or plugin files reachable by the application process.
Title MoviePilot Path Traversal via Cloud Storage Download Handlers
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-06-05T21:42:49.274Z

Updated: 2026-06-08T16:25:30.674Z

Reserved: 2026-06-05T19:08:04.224Z

Link: CVE-2026-11416

cve-icon Vulnrichment

Updated: 2026-06-08T16:22:12.750Z

cve-icon NVD

Status : Deferred

Published: 2026-06-05T22:16:47.127

Modified: 2026-06-08T17:16:37.877

Link: CVE-2026-11416

cve-icon Redhat

No data.