CVE-2026-1588

Source
https://cve.org/CVERecord?id=CVE-2026-1588
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1588.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1588
Published
2026-01-29T13:32:06.240Z
Modified
2026-08-12T03:51:11.453036221Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
jishenghua jshERP installByPath install path traversal
Details

A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.4"
                },
                {
                    "last_affected": "3.4"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/1xxx/CVE-2026-1588.json"
}
References

Affected packages

Git / github.com/jishenghua/jsherp

Affected ranges

Type
GIT
Repo
https://github.com/jishenghua/jsherp
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.0"
        },
        {
            "last_affected": "3.0"
        },
        {
            "introduced": "3.1"
        },
        {
            "last_affected": "3.1"
        },
        {
            "introduced": "3.2"
        },
        {
            "last_affected": "3.2"
        },
        {
            "introduced": "3.3"
        },
        {
            "last_affected": "3.3"
        },
        {
            "introduced": "3.5"
        },
        {
            "last_affected": "3.5"
        },
        {
            "introduced": "3.6"
        },
        {
            "last_affected": "3.6"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "cpe": "cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:*"
}

Affected versions

3.*
3.0
3.1
3.2
3.3
3.5
3.6
v3.*
v3.0
v3.1
v3.2
v3.3
v3.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1588.json"