CVE-2026-81560 | blackms aistack up to 1.6.1 Static File src/web/server.ts req.url path traversal (Issue 57)

SecurityVulns

A vulnerability labeled as problematic has been found in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal.

This vulnerability is documented as CVE-2026-81560. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More