← Terug naar overzicht

LeafWiki versions 0.3.0 through 0.10.0 contain a path traversal vulnerability in the asset rename functionality. Authenticated users with editor permissions can move arbitrary files accessible to the LeafWiki server process into a page's asset directory. This could expose sensitive files such as the application database as downloadable page assets. The vulnerability requires authenticated access with editor-level privileges to exploit. Users are advised to upgrade to version 0.10.1 or later to remediate the issue. As interim mitigations, operators should run the LeafWiki process with least-privilege permissions and restrict editor access to trusted users only. Additionally, limiting the filesystem permissions of the LeafWiki process reduces the potential impact of exploitation.

Affected products

  • LeafWiki 0.10.0
  • LeafWiki 0.3.0
  • LeafWiki 0.4.0
  • LeafWiki 0.5.0
  • LeafWiki 0.6.0
  • LeafWiki 0.7.0
  • LeafWiki 0.8.0
  • LeafWiki 0.9.0

Related CVE's

  • CVE-2026-53528

Categories

  • Data Breach & Exfiltration
  • Web Technologies