VulnerabilityAnalyzed
CVE-2026-6815
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider.
MEDIUM 5.9EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- casbin/casdoor
- Source
- cret@cert.org
References
- https://kb.cert.org/vuls/id/937808Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/937808Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.