CVE-2026-97323 | YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08 File Upload MpMaterialServiceImpl.java getOriginalFilename path traversal

SecurityVulns

A vulnerability described as critical has been identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing a manipulation can lead to path traversal.

This vulnerability is registered as CVE-2026-97323. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More