CVE-2026-54567 | jugmac00 Flask-Reuploaded up to 1.5.x Extension flask_uploads.py UploadSet.save Name incomplete blacklist
A vulnerability identified as critical has been detected in jugmac00 Flask-Reuploaded up to 1.5.x. The affected element is the function UploadSet.save of the file src/flask_uploads/flask_uploads.py of the component Extension Handler. Performing a manipulation of the argument Name results in incomplete blacklist.
This vulnerability is cataloged as CVE-2026-54567. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More