knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 16:18
Updated : 2026-09-10 19:58
NVD link : CVE-2026-88937
Mitre link : CVE-2026-88937
CVE.ORG link : CVE-2026-88937
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
