CVE-2026-66415
🟡 Monitoruj
W Leantime 3.6.2 luka SSRF i LFI pozwala uwierzytelnionym atakującym na odczyt wewnętrznych zasobów.
CVSS
8.5
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the server filesystem.
lfi path-traversal ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-07-30 19:18:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-31 12:16:55 UTC |
Referencje
- https://github.com/Leantime/leantime (disclosure@vulncheck.com)
- https://github.com/Leantime/leantime/pull/3656 (disclosure@vulncheck.com)
- https://github.com/javokhir-sec/CVE-PoC-Hub/security/advisories/GHSA-gphg-6h4g-mg22 (disclosure@vulncheck.com)
- https://www.vulncheck.com/advisories/leantime-server-side-request-forgery-and-local-file-inclusion-in-blueprints-import (disclosure@vulncheck.com)