Unrated severityOSV Advisory· Published Jan 30, 2026· Updated Feb 2, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller
CVE-2026-0963
Description
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
Affected products
2- Range: v4.7.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.com/crafty-controller/crafty-4/-/issues/660mitreissue-trackingpermissions-required
News mentions
0No linked articles in our index yet.