Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.
References
| Link | Resource |
|---|---|
| https://growi.co.jp/news/44/ | |
| https://jvn.jp/jp/JVN38788367/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-11 10:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-41951
Mitre link : CVE-2026-41951
CVE.ORG link : CVE-2026-41951
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
