CVE-2026-81560: blackms aistack Static File server.ts path traversal
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered exposed?
blackms aistack versions up to 1.6.1 are affected in the Static File Handler implemented in src/web/server.ts. Exposure requires that the vulnerable static-file functionality be reachable remotely.
What does an attacker need to exploit this issue?
The attack can be performed remotely without stated authentication or user interaction requirements. Exploitation involves manipulating the req.url argument to trigger path traversal, and a public exploit is available.
Is a vendor fix available?
The provided information does not identify a fixed version. The project was reportedly notified through an issue report but had not responded at the time of publication.