VYPR

DYMO Connect Desktop

by Newell Brands

CVEs (1)

  • CVE-2026-76796MedSep 15, 2026
    risk 0.26cvss 4.0epss

    The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside the intended scope. Fixed in 1.6.2. The…