Path Traversal Vulnerability in DSpace Repository Software
CVE-2026-49831

5.5MEDIUM

Key Information:

Vendor

Dspace

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-49831?

The DSpace open source repository software contains a path traversal vulnerability in the Curation Task feature. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the curator was able to specify an output path using the -r parameter, which is designed to stream results of curation tasks. However, this path was not restricted, allowing users to write to any directory that is writable by the DSpace application (commonly under the 'tomcat' user). This flaw can potentially lead to exposure of sensitive files and unauthorized access to system directories.

Affected Version(s)

DSpace < 7.6.7 < 7.6.7

DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4

DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.