A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traversal. It is possible to initiate the attack remotely.
{
"nvd_published_at": "2025-11-17T06:15:43Z",
"github_reviewed": true,
"github_reviewed_at": "2025-11-26T22:02:07Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-22"
]
}