CVE-2026-45419: DataEase: Arbitrary File Write Vulnerability
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled staticResource names and Base64 content, allowing path traversal and arbitrary file writes because only / was used when extracting the file name. This issue is fixed in version 2.10.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.23
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45419?
CVE-2026-45419 has a risk score of 71, indicating a significant potential impact.
How do I fix CVE-2026-45419?
To fix CVE-2026-45419, upgrade DataEase to version 2.10.23 or later.
What vulnerable versions are affected by CVE-2026-45419?
CVE-2026-45419 affects all versions of DataEase prior to 2.10.23.
What type of vulnerability is CVE-2026-45419?
CVE-2026-45419 is classified as a Path Traversal vulnerability.
What are the potential consequences of CVE-2026-45419?
The potential consequences of CVE-2026-45419 include unauthorized file writing due to attacker-controlled inputs.