VYPR
Medium severity6.3NVD Advisory· Published Aug 13, 2026

CVE-2026-19756

CVE-2026-19756

Description

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Dromara/Lamp Cloudreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=5.10.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.