Path Traversal Vulnerability in Drogon Up to 1.9.13-1/10.0-beta.3
CVE-2026-105144
6.9MEDIUM
What is CVE-2026-105144?
A vulnerability has been identified in Drogon versions up to 1.9.13 and 10.0-beta.3 on Windows. This flaw lies within the StaticFileRouter::route function located in lib/src/StaticFileRouter.cc, which can be exploited to perform path traversal attacks. Such an attack may allow an unauthorized user to access files and directories outside of the intended file system boundaries. The vulnerability can be executed remotely, and though the vendor was informed prior to its public disclosure, there has been no response. Organizations using affected versions are advised to apply the necessary updates or mitigations to secure their applications.
Affected Version(s)
Drogon 1.9.13-1
Drogon 10.0-beta.0
Drogon 10.0-beta.1
