CVE-2026-77914

Source
https://cve.org/CVERecord?id=CVE-2026-77914
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77914.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77914
Aliases
  • GHSA-m5rw-jcrm-mmwc
Published
2026-08-24T16:07:58.448Z
Modified
2026-08-27T11:47:35.570404096Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
rConfig Core 8.0.0 < 8.2.13 Core Path Traversal via Export Download Endpoint
Details

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename parameter with traversal sequences to escape the intended export directory and access files outside it that are readable by the application process.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77914.json"
}
References

Affected packages

Git / github.com/rconfig/rconfig

Affected ranges

Type
GIT
Repo
https://github.com/rconfig/rconfig
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.2.13"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

core-8.*
core-8.0.0
core-8.0.1
core-8.0.2
core-8.1.0
core-8.1.1
core-8.1.2
core-8.1.3
core-8.2.0
core-8.2.10
core-8.2.11
core-8.2.12
core-8.2.3
core-8.2.4
core-8.2.5
core-8.2.6
core-8.2.7
core-8.2.8
core-8.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77914.json"