Path Traversal Vulnerability in Dromara Lamp-Cloud Software
CVE-2026-19756
Key Information:
- Vendor
Dromara
- Status
- Vendor
- CVE Published:
- 13 August 2026
Badges
What is CVE-2026-19756?
A path traversal vulnerability has been identified in the Dromara Lamp-Cloud software's Code Generator component, specifically within the DefGenProjectController.java file. Attackers can exploit this vulnerability by manipulating the outputDir, parent, or projectPrefix arguments, enabling remote file access. Despite the project maintainers being notified of this issue through an early report, there has been no response to remediate or mitigate the threat. This vulnerability poses a considerable risk to users utilizing affected versions up to 5.10.0, as it could facilitate unauthorized access to the file system.
Affected Version(s)
lamp-cloud 5.0
lamp-cloud 5.1
lamp-cloud 5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
