VYPR

Zfile

by Zfile Dev

CVEs (1)

  • CVE-2026-91144HigSep 14, 2026
    risk 0.49cvss 7.5epss

    ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the…