DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dspace
Dspace dspace |
|
| Vendors & Products |
Dspace
Dspace dspace |
Wed, 02 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0. | |
| Title | DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path Traversal Vulnerability) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-09-02T17:17:29.261Z
Updated: 2026-09-02T19:01:29.463Z
Reserved: 2026-06-01T18:50:36.056Z
Link: CVE-2026-49831
No data.
Status : Awaiting Analysis
Published: 2026-09-02T18:19:32.683
Modified: 2026-09-09T21:05:23.237
Link: CVE-2026-49831
No data.