A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component codetaskfiles. Executing a manipulation can lead to path traversal. The attack can be launched remotely. This patch is called 35d97bca0531894da36a85aedb95312da1bd5b7a. It is best practice to apply a patch to resolve this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82112.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "2.13.0"
},
{
"last_affected": "2.13.0"
},
{
"introduced": "2.13.1"
},
{
"last_affected": "2.13.1"
},
{
"introduced": "2.13.2"
},
{
"last_affected": "2.13.2"
}
]
}
],
"cwe_ids": [
"CWE-22"
],
"cna_assigner": "VulDB"
}