CVE-2026-45533

Source
https://cve.org/CVERecord?id=CVE-2026-45533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45533
Aliases
  • GHSA-mwr5-hw6p-cqmg
Published
2026-07-15T19:39:08Z
Modified
2026-08-12T16:24:38Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H CVSS Calculator
Summary
DataEase: Path Traversal Vulnerability
Details

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in the bulk delete API endpoint and pass attacker-controlled identifiers to ExportCenterManage.delete, allowing recursive deletion of arbitrary server directories through export task cleanup. This issue is fixed in version 2.10.23.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45533.json"
}
References

Affected packages

Git / github.com/dataease/dataease

Affected ranges

Type
GIT
Repo
https://github.com/dataease/dataease
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.23"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.0.0
v2.*
v2.10.0
v2.10.1
v2.10.10
v2.10.11
v2.10.12
v2.10.13
v2.10.14
v2.10.15
v2.10.16
v2.10.17
v2.10.18
v2.10.19
v2.10.2
v2.10.20
v2.10.21
v2.10.22
v2.10.3
v2.10.4
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.2.0
v2.3.0
v2.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45533.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "204502022704520059990545729452998135465",
            "length": 381
        },
        "id": "CVE-2026-45533-33d6075a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/dba08037232cf4760fd9e9f36f4bef4e9330d041",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/exportCenter/manage/ExportCenterManage.java",
            "function": "delete"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "187168418633645533846068730440517493336",
                "206621793751654566391304860310118263046",
                "294030223774061472009293893002029132624",
                "298110959276219203352219633664903526287",
                "307860605108267082350560529648192892787",
                "139904788295246254198251394497498957745",
                "231820323389915976460905632171353389699",
                "302314471312831070969448425502804928433",
                "212098503657362162296282760553377966943",
                "152573336223543483135976667772093004610",
                "15063197104129462235417475101656848605",
                "262498199538085262002412757745936207067",
                "83004244989414224013876399500290593383",
                "119716568899591181549424800039012077166",
                "109038925321580943198988659418288551861",
                "318731119132832605479731602542262244401",
                "27997890785480148088378176231489654906"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-45533-75b07192",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/dataease/dataease/commit/dba08037232cf4760fd9e9f36f4bef4e9330d041",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/exportCenter/manage/ExportCenterManage.java"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:24:38Z"