CVE-2026-103533 | David-Crty databasement up to 1.7.1 database-servers API Endpoint RestoreRequest.php schema_name path traversal (GHSA-x225-463f-pgww)

SecurityVulns

A vulnerability, which was classified as problematic, was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.

This vulnerability is cataloged as CVE-2026-103533. The attack may be launched remotely. Furthermore, there is an exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More