CVE-2026-19757: Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19757?
CVE-2026-19757 has a severity rating of 7.3, classified as high.
What does CVE-2026-19757 affect?
CVE-2026-19757 affects the FileAnyoneController.java of the Dromara lamp-cloud component File-Upload Controller up to version 5.10.0.
How do I fix CVE-2026-19757?
To fix CVE-2026-19757, update your Dromara lamp-cloud implementation to a version later than 5.10.0.
What type of vulnerability is CVE-2026-19757?
CVE-2026-19757 is classified as a path traversal vulnerability.
What can attackers do with CVE-2026-19757?
Attackers can exploit CVE-2026-19757 to perform path traversal attacks remotely.