Cross-Platform PowerShell Framework Vulnerability in Pode
CVE-2026-42598
6.9MEDIUM
What is CVE-2026-42598?
The Pode framework, used for developing cross-platform PowerShell applications, is susceptible to a path traversal vulnerability that allows unauthorized access to sensitive files. When users make requests to Static Routes, they might inadvertently retrieve contents from critical system files, such as the hosts file located in the Windows System32 directory. This issue affects Pode versions from 2.4.0 up until 2.12.9. Upgrading to version 2.13.0 or later resolves the vulnerability and secures the application against this type of exploitation.
Affected Version(s)
Pode < 2.13.0
