CVE-2026-5258 | Sanster IOPaint 1.5.3 File Manager file_manager.py _get_file filename path traversal
A vulnerability identified as critical has been detected in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the argument filename results in path traversal.
This vulnerability is reported as CVE-2026-5258. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More