CVE-2026-15527 | better-auth better-icons up to 1.0.5 scan_project_icons/sync_icon icons_file path traversal (Issue 18)

SecurityVulns

A vulnerability was found in better-auth better-icons up to 1.0.5 and classified as critical. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument icons_file leads to path traversal.

This vulnerability is traded as CVE-2026-15527. An attack has to be approached locally. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More