VYPR
Medium severity4.9OSV Advisory· Published Aug 5, 2026· Updated Aug 26, 2026

CVE-2026-71283

CVE-2026-71283

Description

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role (@has_permission("admin")).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Fledge Iot/FledgeOSV2 versions
    v3.1.0, v3.0.0, v2.6.0, …+ 1 more
    • (no CPE)range: v3.1.0, v3.0.0, v2.6.0, …
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.