CVE-2026-64838

Source
https://cve.org/CVERecord?id=CVE-2026-64838
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64838.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64838
Published
2026-09-10T13:51:07Z
Modified
2026-09-12T03:46:47Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
ICEcoder through 8.1 Path Traversal via oldFileName Parameter
Details

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64838.json"
}
References

Affected packages

Git / github.com/icecoder/icecoder

Affected ranges

Type
GIT
Repo
https://github.com/icecoder/icecoder
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.1"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "8.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

8.*
8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64838.json"