VYPR

Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb

by Theopaid

CVEs (1)

  • CVE-2026-67185Jul 28, 2026
    risk 0.00cvss epss 0.00

    TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without…