CVE-2026-71805

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 22:18

Updated : 2026-09-10 16:17


NVD link : CVE-2026-71805

Mitre link : CVE-2026-71805

CVE.ORG link : CVE-2026-71805


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type