Cross-Platform PowerShell Framework Vulnerability in Pode
CVE-2026-42598

6.9MEDIUM

Key Information:

Vendor

Badgerati

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-42598?

The Pode framework, used for developing cross-platform PowerShell applications, is susceptible to a path traversal vulnerability that allows unauthorized access to sensitive files. When users make requests to Static Routes, they might inadvertently retrieve contents from critical system files, such as the hosts file located in the Windows System32 directory. This issue affects Pode versions from 2.4.0 up until 2.12.9. Upgrading to version 2.13.0 or later resolves the vulnerability and secures the application against this type of exploitation.

Affected Version(s)

Pode < 2.13.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.