CVE-2026-19758

Source
https://cve.org/CVERecord?id=CVE-2026-19758
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19758.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19758
Published
2026-08-13T23:30:09.251Z
Modified
2026-08-16T03:30:52.480789396Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal
Details

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19758.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0"
                },
                {
                    "last_affected": "5.0"
                },
                {
                    "introduced": "5.1"
                },
                {
                    "last_affected": "5.1"
                },
                {
                    "introduced": "5.2"
                },
                {
                    "last_affected": "5.2"
                },
                {
                    "introduced": "5.3"
                },
                {
                    "last_affected": "5.3"
                },
                {
                    "introduced": "5.7"
                },
                {
                    "last_affected": "5.7"
                },
                {
                    "introduced": "5.8"
                },
                {
                    "last_affected": "5.8"
                },
                {
                    "introduced": "5.9"
                },
                {
                    "last_affected": "5.9"
                },
                {
                    "introduced": "5.10.0"
                },
                {
                    "last_affected": "5.10.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/dromara/lamp-cloud

Affected ranges

Type
GIT
Repo
https://github.com/dromara/lamp-cloud
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "5.4"
        },
        {
            "last_affected": "5.4"
        },
        {
            "introduced": "5.5"
        },
        {
            "last_affected": "5.5"
        },
        {
            "introduced": "5.6"
        },
        {
            "last_affected": "5.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

5.*
5.4
5.4.0
5.5
5.5.0
5.5.1
5.6
5.6.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19758.json"