VYPR

laranode

by Crivion

CVEs (1)

  • CVE-2026-100520HigSep 26, 2026
    risk 0.50cvss 8.8epss —

    Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to…