CVE-2026-50186 | RARgames 4gaBoards up to 3.3.7 Download download.js path.join filename path traversal
A vulnerability described as problematic has been identified in RARgames 4gaBoards up to 3.3.7. The affected element is the function path.join of the file server/api/controllers/boards/download.js of the component Download. Executing a manipulation of the argument filename can lead to path traversal.
This vulnerability appears as CVE-2026-50186. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More