CVE-2026-49831

Source
https://cve.org/CVERecord?id=CVE-2026-49831
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49831.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49831
Aliases
Published
2026-09-02T17:17:29.261Z
Modified
2026-09-04T03:46:00.446231613Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path Traversal Vulnerability)
Details

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49831.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "= 10-rc1"
                },
                {
                    "last_affected": "= 10-rc1"
                }
            ]
        }
    ],
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/dspace/dspace

Affected ranges

Type
GIT
Repo
https://github.com/dspace/dspace
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.6.7"
        },
        {
            "introduced": "8.0-rc1"
        },
        {
            "fixed": "8.4"
        },
        {
            "introduced": "9.0-rc1"
        },
        {
            "fixed": "9.3"
        }
    ]
}

Affected versions

dspace-3.*
dspace-3.0
dspace-3.0-rc1
dspace-3.0-rc2
dspace-3.0-rc3
dspace-4.*
dspace-4.0
dspace-4.0-rc1
dspace-4.0-rc2
dspace-4.0-rc3
dspace-5.*
dspace-5.0
dspace-5.0-rc1
dspace-5.0-rc2
dspace-5.0-rc3
dspace-6.*
dspace-6.0
dspace-6.0-pre-DS-2701
dspace-6.0-rc1
dspace-6.0-rc2
dspace-6.0-rc3
dspace-6.0-rc4
dspace-7.*
dspace-7.0
dspace-7.0-beta1
dspace-7.0-beta2
dspace-7.0-beta2.1
dspace-7.0-beta3
dspace-7.0-beta4
dspace-7.0-beta4.1
dspace-7.0-beta5
dspace-7.0-preview-1
dspace-7.1
dspace-7.2
dspace-7.3
dspace-7.4
dspace-7.5
dspace-7.6
dspace-7.6.1
dspace-7.6.2
dspace-7.6.3
dspace-7.6.4
dspace-7.6.5
dspace-7.6.6
dspace-8.*
dspace-8.0
dspace-8.0-rc1
dspace-8.1
dspace-8.2
dspace-8.3
dspace-9.*
dspace-9.0
dspace-9.0-rc1
dspace-9.1
dspace-9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49831.json"