LeafWiki versions 0.3.0 through 0.10.0 contain a path traversal vulnerability in the asset rename functionality. Authenticated users with editor permissions can move arbitrary files accessible to the LeafWiki server process into a page's asset directory. This could expose sensitive files such as the application database as downloadable page assets. The vulnerability requires authenticated access with editor-level privileges to exploit. Users are advised to upgrade to version 0.10.1 or later to remediate the issue. As interim mitigations, operators should run the LeafWiki process with least-privilege permissions and restrict editor access to trusted users only. Additionally, limiting the filesystem permissions of the LeafWiki process reduces the potential impact of exploitation.