Path Traversal Vulnerability in Laranode Affects Web Application Security
CVE-2026-100520
8.7HIGH
What is CVE-2026-100520?
Laranode versions prior to 1.2.1 exhibit a path traversal vulnerability within the POST /filemanager/upload-file endpoint. This flaw permits authenticated users to manipulate directory traversal sequences in the path parameter, allowing them to write arbitrary files outside their designated home directories. Consequently, attackers could execute PHP files in other tenants' web roots, posing a significant risk to the integrity of the application and its users.
Affected Version(s)
Laranode 0 < 1.2.1
