Link-Following Vulnerability in thClaws API by thClaws
CVE-2026-108839

2.3LOW

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108839?

The thClaws API version through 0.141.0 is susceptible to a link-following vulnerability in the post_inputs handler of the v1 API POST /v1/inputs endpoint. This flaw allows an attacker to exploit symlinks, potentially enabling unauthorized file writes or truncations outside the designated workspace by leveraging authenticated uploads. With the ability to plant symlinks under the allowed inputs/ prefix, attackers can manipulate file systems with increased privileges, creating significant security risks for users.

Affected Version(s)

thClaws 0 <= 0.141.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.