Path Traversal Vulnerability in Taoofagi Easegen-Admin Software
CVE-2026-4285
Key Information:
- Vendor
Taoofagi
- Status
- Vendor
- CVE Published:
- 16 March 2026
Badges
What is CVE-2026-4285?
A path traversal vulnerability exists within the Taoofagi Easegen-Admin software, specifically in the 'recognizeMarkdown' function of the 'Pdf2MdUtil.java' file. This vulnerability allows attackers to manipulate the 'fileUrl' argument, potentially gaining unauthorized access to the underlying filesystem. The vulnerability can be exploited remotely, and the exploit is publicly available, posing a risk to users of the affected versions. The company has not responded to early disclosures regarding the issue, raising concerns over user safety and the need for immediate remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
easegen-admin 8f87936ac774065b92fb20aab55b274a6ea76433
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
