CVE-2026-108772 | bleenco abstruse up to 2.1.0 Cache Endpoint download_cache.go filepath.Join file path traversal

SecurityVulns

A vulnerability labeled as problematic has been found in bleenco abstruse up to 2.1.0. This issue affects the function filepath.Join of the file server/api/worker/download_cache.go of the component Cache Endpoint. Such manipulation of the argument File leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-108772. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More