CVE-2026-72569 | cube-root directory-serve up to 1.3.7 file-remove.js File path traversal
A vulnerability has been found in cube-root directory-serve up to 1.3.7 and classified as critical. Affected is an unknown function of the file lib/middleware/file-remove.js. This manipulation of the argument File causes path traversal.
This vulnerability is tracked as CVE-2026-72569. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More