Arbitrary File Read and Write Vulnerability in OpenSave by Liquid.co
CVE-2026-103398

8.6HIGH

Key Information:

Vendor

Liquid-co

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103398?

The vulnerability in OpenSave versions up to 2.4.0 stems from improper validation of save paths provided by peer systems. This flaw allows attackers to manipulate the save paths during manifest requests, enabling them to access and alter files beyond the intended directories. By exploiting this vulnerability, malicious actors could read sensitive files or write malicious data by passing controlled save paths through the manifest and synchronization interfaces. Immediate remediation is advised to prevent unauthorized file manipulation.

Affected Version(s)

OpenSave 0 <= 2.4.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mansurmavlankulov
.