CVE-2026-72572 | o1lab xmysql xapi lib/xapi.js path.join Name path traversal

SecurityVulns

A vulnerability was found in o1lab xmysql. It has been rated as problematic. This vulnerability affects the function path.join of the file lib/xapi.js of the component xapi. The manipulation of the argument Name leads to path traversal.

This vulnerability is documented as CVE-2026-72572. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More