yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 22:16
Updated : 2026-08-31 20:12
NVD link : CVE-2026-75333
Mitre link : CVE-2026-75333
CVE.ORG link : CVE-2026-75333
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
