CVE-2026-88394: WookTeam WookTeam vulnerability
WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storagepath($file) without any path normalization or directory boundary check, so directory traversal (../) escapes the storage/ directory and response()->download() streams any file readable by the web server process.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Any WookTeam deployment running version 1.6.6 or earlier is exposed if the project task export endpoint is reachable and the web server process can read sensitive files outside the storage directory.
What does an attacker need to exploit it?
An attacker needs to send a request to /api/project/task/export with a data parameter containing crafted JSON. The file value must include directory-traversal sequences such as ../ to target a readable file outside storage/.
What files can be accessed?
The endpoint can stream arbitrary files that are readable by the web server process. Files inaccessible to that process are not readable through this issue.