NewsFortinet PSIRT2026-04-14 07:00 UTC
Path Traversal on File Content Extraction connector
Teaser from the source
CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSOAR may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions. Revised on 2026-04-14 00:00:00
This is the RSS-feed teaser. Read the full article at the original source.
Read at Fortinet PSIRT →More on Extraction
Other advisories
- osv:GHSA-fr26-jjhm-638cnonepyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
- ghsa:GHSA-fr26-jjhm-638chighpyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
- osv:CLEANSTART-2026-MN51569nonetar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory
- CVE-2026-107290nonePydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
- CVE-2026-107290mediumPydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
- osv:CVE-2026-107290nonePydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
- CVE-2026-106451noneyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
- CVE-2026-106451highyawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
Other news entries
- Newsthehackernews2026-10-01OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
- Newsthehackernews2026-09-09U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
- Newscsoonline2026-08-17Why data quality dictates security operations success
- Newsthehackernews2026-07-20New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
- Newssiemens-productcertSSA-622830 V1.0: Multiple Vulnerabilities in JT2Go and Teamcenter Visualization
Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-116
ID