CVE-2026-49836 | psd-tools up to 1.17.0 Smart Object SmartObject.save/SmartObject.open fullPath path traversal

SecurityVulns

A vulnerability, which was classified as critical, was found in psd-tools up to 1.17.0. Impacted is the function SmartObject.save/SmartObject.open of the component Smart Object Handler. The manipulation of the argument fullPath results in path traversal.

This vulnerability is cataloged as CVE-2026-49836. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More