Path Traversal Vulnerability in DSpace Repository Software
CVE-2026-49831
5.5MEDIUM
What is CVE-2026-49831?
The DSpace open source repository software contains a path traversal vulnerability in the Curation Task feature. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the curator was able to specify an output path using the -r parameter, which is designed to stream results of curation tasks. However, this path was not restricted, allowing users to write to any directory that is writable by the DSpace application (commonly under the 'tomcat' user). This flaw can potentially lead to exposure of sensitive files and unauthorized access to system directories.
Affected Version(s)
DSpace < 7.6.7 < 7.6.7
DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4
DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3
