CVE-2026-103533

Source
https://cve.org/CVERecord?id=CVE-2026-103533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103533
Aliases
  • GHSA-x225-463f-pgww
Published
2026-10-01T02:45:11Z
Modified
2026-10-02T03:47:26Z
Severity
  • 1.2 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 path traversal
Details

A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 1.7.2 will fix this issue. You should upgrade the affected component.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-22"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103533.json"
}
References

Affected packages

Git / github.com/david-crty/databasement

Affected ranges

Type
GIT
Repo
https://github.com/david-crty/databasement
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.7.0"
        },
        {
            "last_affected":  "1.7.0"
        },
        {
            "introduced":  "1.7.1"
        },
        {
            "last_affected":  "1.7.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.7.0
1.7.1
v1.*
v1.7.0
v1.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103533.json"