CVE-2026-108158: plugNmeet Server through 2.5.2 Path Traversal via /api/whiteboard/convert
plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any meeting participant can exploit the vulnerable whiteboard conversion endpoint. The attacker needs participant-level access, but no user interaction is required.
What data can be exposed?
An attacker can use crafted filePath values containing ../ sequences to cause server text or office documents to be converted into page images. The resulting images can then be retrieved without authentication from /download/uploadedFile/.
Are systems running the default configuration affected?
The available information does not identify a configuration prerequisite or mitigation. Systems running plugNmeet Server through version 2.5.2 should be treated as affected if meeting participants can access the whiteboard conversion endpoint.