Critical severity9.9OSV Advisory· Published Jan 30, 2026· Updated Jun 17, 2026
CVE-2026-0963
CVE-2026-0963
Description
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:craftycontrol:crafty_controller:4.7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:craftycontrol:crafty_controller:4.7.0:*:*:*:*:*:*:*
- (no CPE)
v4.7.0+ 1 more
- (no CPE)range: v4.7.0
- (no CPE)
Patches
Vulnerability mechanics
References
1- gitlab.com/crafty-controller/crafty-4/-/issues/660nvdBroken Link
News mentions
0No linked articles in our index yet.