yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in yx-image-recognition v1.0 |
Thu, 27 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in yx-image-recognition v1.0 | |
| Weaknesses | CWE-22 |
Wed, 26 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-26T00:00:00.000Z
Updated: 2026-08-27T15:40:11.867Z
Reserved: 2026-08-17T00:00:00.000Z
Link: CVE-2026-75333
Updated: 2026-08-27T15:39:44.152Z
Status : Deferred
Published: 2026-08-26T22:16:29.327
Modified: 2026-08-31T20:12:02.273
Link: CVE-2026-75333
No data.