CVE-2026-71279 | Koenkk Zigbee2MQTT up to 2.12.0 ExternalJSExtension externalJS.ts ExternalJSExtension.getFilePath Name path traversal
A vulnerability described as critical has been identified in Koenkk Zigbee2MQTT up to 2.12.0. The affected element is the function ExternalJSExtension.getFilePath of the file lib/extension/externalJS.ts of the component ExternalJSExtension. Such manipulation of the argument Name leads to path traversal.
This vulnerability is documented as CVE-2026-71279. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More