CVE-2026-13716 PUBLISHED

Path Traversal: '.../...//' in Crafty Controller

Assigner: GitLab
Reserved: 29.06.2026 Published: 11.08.2026 Updated: 11.08.2026

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
CVSS Score: 9.1

Product Status

Vendor Arcadia Technology, LLC
Product Crafty Controller
Versions Default: unaffected
  • affected from 4.4.0 to 4.10.7 (incl.)

Solutions

Upgrade to version 4.10.8

Credits

  • Thank you to [George Chen](https://gitlab.com/geo-chen) on Gitlab for reporting this issue. Thank you to [Metin Durmuş](https://gitlab.com/durmus38metin) on GitLab for contributing to this issue. finder

References

Problem Types

  • CWE-35: Path Traversal: '.../...//' CWE