CVE-2026-45532: DataEase has a Path Traversal Vulnerability
Published Aug 18, 2026
·Updated
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the FILESEPARATOR is \, while the server only filters the / character during string truncation. The vulnerability has been fixed in v2.10.23. No known workarounds are available.
Affected Software
1 affected component
DataEase<2.10.23
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataEaseto a version that resolves this vulnerability.Fixed in 2.10.23
Event History
Aug 18, 2026
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
DataEase versions prior to 2.10.23 are affected when running on Windows, where backslashes can bypass the server's filtering of forward slashes. The issue is fixed in version 2.10.23.
2
What should I do if I cannot patch immediately?
No known workaround is available. Upgrade DataEase to version 2.10.23.