Path Traversal Vulnerability in DTStack Taier Upload Controller
CVE-2026-19761
5.1MEDIUM
What is CVE-2026-19761?
A path traversal vulnerability exists in DTStack Taier version 1.4.0, specifically within the MultipartFile.getOriginalFilename function of the UploadController.java component. This issue allows an attacker to manipulate file arguments and potentially access files outside of the intended directory structure. An attacker can initiate this attack remotely, making it imperative for users of this version to upgrade to version 1.5.0, which includes a patch addressing the vulnerability. For details on the patch, refer to the commit identifier 572773c4315e23e51e30115151cb091749a8d03e.
Affected Version(s)
Taier 1.4.0
Taier 1.5.0
