CVE-2026-19757

Source
https://cve.org/CVERecord?id=CVE-2026-19757
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19757.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19757
Published
2026-08-13T23:15:09.882Z
Modified
2026-08-16T03:31:22.640292084Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal
Details

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19757.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "5.0"
                },
                {
                    "last_affected": "5.0"
                },
                {
                    "introduced": "5.1"
                },
                {
                    "last_affected": "5.1"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "last_affected": "5.2"
                },
                {
                    "introduced": "5.3"
                },
                {
                    "last_affected": "5.3"
                },
                {
                    "introduced": "5.7"
                },
                {
                    "last_affected": "5.7"
                },
                {
                    "introduced": "5.8"
                },
                {
                    "last_affected": "5.8"
                },
                {
                    "introduced": "5.9"
                },
                {
                    "last_affected": "5.9"
                },
                {
                    "introduced": "5.10.0"
                },
                {
                    "last_affected": "5.10.0"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/dromara/lamp-cloud

Affected ranges

Type
GIT
Repo
https://github.com/dromara/lamp-cloud
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "5.4"
        },
        {
            "last_affected": "5.4"
        },
        {
            "introduced": "5.5"
        },
        {
            "last_affected": "5.5"
        },
        {
            "introduced": "5.6"
        },
        {
            "last_affected": "5.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

5.*
5.4
5.4.0
5.5
5.5.0
5.5.1
5.6
5.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19757.json"