CVE-2026-19326: Jevon-Zhong Ai-doctor filemanagement.service.ts deleteImage path traversal
A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the file ai-doctor-server/src/filemanagement/filemanagement.service.ts. Performing a manipulation of the argument imagePath results in path traversal. The attack must be initiated from a local position. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19326?
The severity of CVE-2026-19326 is rated as medium with a score of 4.4.
How do I fix CVE-2026-19326?
To fix CVE-2026-19326, validate and sanitize the imagePath argument to prevent path traversal exploits.
What impact does CVE-2026-19326 have on systems?
CVE-2026-19326 can allow attackers to delete arbitrary files on the server through path traversal.
Which software is affected by CVE-2026-19326?
CVE-2026-19326 affects Jevon-Zhong Ai-doctor version 0.0.1.
What type of vulnerability is CVE-2026-19326?
CVE-2026-19326 is classified as a path traversal vulnerability.