CVE-2026-56815 PUBLISHED

Assigner: mitre
Reserved: 23.06.2026 Published: 23.06.2026 Updated: 23.06.2026

pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.4

Product Status

Vendor rasta-mouse
Product pwnlift
Versions Default: unaffected
  • affected from 0 to d7a95449d9ee1ea09ec1529286685f6187afbbed (excl.)

References

Problem Types

  • CWE-61 UNIX Symbolic Link (Symlink) Following CWE