Path Traversal Vulnerability in Vaadin Affects Node.js Extraction
CVE-2026-2741
2.3LOW
What is CVE-2026-2741?
A security vulnerability in the Vaadin Framework allows specially crafted ZIP archives to escape the intended extraction directory during the automatic download and extraction of Node.js. This issue affects multiple versions and can be exploited through various attack vectors including DNS hijacking or supply chain compromises. Attackers can leverage this vulnerability to place malicious files outside the secure directory, posing a risk to the system's integrity. Users are advised to upgrade to specific patched versions or utilize a compatible preinstalled Node.js to mitigate this risk.
Affected Version(s)
flow 2.2.0 <= 2.13.0
flow 3.0.0 <= 23.6.7
flow 24.0.0 <= 24.9.9
