CVE-2026-18903 | yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4 FileController.java path path traversal
A vulnerability, which was classified as critical, has been found in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal.
The identification of this vulnerability is CVE-2026-18903. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More