CVE-2026-6815 PUBLISHED

CVE-2026-6815

Assigner: certcc
Reserved: 21.04.2026 Published: 11.05.2026 Updated: 11.05.2026

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

Product Status

Vendor Casdoor
Product Casdoor
Versions
  • affected from 0 to v2.328.0 (incl.)

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')