THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90445 — An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traver

[NVD] CVE-2026-90445 — An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traver

mednvdPublished 2026-09-11

CVE-2026-90445 CVSS: None Published: 2026-09-11T22:16:46.510

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extract

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90445