Unauthenticated Path Traversal in Jotty·Page by FCCView
CVE-2026-42564
8.2HIGH
What is CVE-2026-42564?
Jotty·Page, a self-hosted application designed for checklists and notes, is susceptible to an unauthenticated path traversal issue prior to version 1.22.0. This vulnerability occurs in the /api/app-icons/[filename] API endpoint, where the provided filename parameter is directly incorporated into a filesystem path without proper validation. As a result, this flaw permits unauthorized read access to files beyond the intended directory, potentially compromising sensitive information.
Affected Version(s)
jotty < 1.22.0
