Path Traversal Vulnerability in YunaiV RUOYI-VUE-PRO File Upload Service
CVE-2026-13528
Key Information:
- Vendor
Yunaiv
- Status
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13528?
A path traversal vulnerability exists in the YunaiV RUOYI-VUE-PRO framework's file upload endpoint. This vulnerability arises in the 'generateUploadPath' function within the FileServiceImpl.java file. An attacker could manipulate inputs to exploit the vulnerability, potentially allowing unauthorized access to sensitive files on the server. This issue has been publicly disclosed, and it is strongly recommended that users apply the patch (commit ID: 4ae3f6b2c9883978837638c14e3d18419819eeb0) to mitigate risk.
Affected Version(s)
ruoyi-vue-pro 2026.04-jdk8-SNAPSHOT
ruoyi-vue-pro 2026.04-jdk8-SNAPSHOT
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
