Path Traversal Vulnerability in Jevon-Zhong Ai-doctor Application
CVE-2026-19326

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 August 2026

What is CVE-2026-19326?

A path traversal vulnerability exists in Jevon-Zhong Ai-doctor version 0.0.1, specifically within the deleteImage function of the filemanagement.service.ts file. This vulnerability allows local attackers to manipulate the imagePath argument, potentially gaining unauthorized access to files outside the intended directory. Although the issue was reported to the developers, no response has been recorded, urging users to take precautionary measures until a patch is released.

Affected Version(s)

Ai-doctor 0.0.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu03 (VulDB User)
VulDB CNA Team
.