CVE-2026-50186 | RARgames 4gaBoards up to 3.3.7 Download download.js path.join filename path traversal

SecurityVulns

A vulnerability described as problematic has been identified in RARgames 4gaBoards up to 3.3.7. The affected element is the function path.join of the file server/api/controllers/boards/download.js of the component Download. Executing a manipulation of the argument filename can lead to path traversal.

This vulnerability appears as CVE-2026-50186. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More