Path Traversal Vulnerability in DSpace Repository Software
CVE-2026-49833
5.5MEDIUM
What is CVE-2026-49833?
A path traversal vulnerability in DSpace allows attackers with administrator credentials to exploit the COAR Notify / LDN service. By manipulating file input streams, an attacker can bypass security checks, leading to potential exposure of sensitive information stored elsewhere in the file system. The issue arises when the LDN class does not properly restrict file access to a designated base path, allowing untrusted files to be interpreted. This vulnerability affects specific versions of DSpace and has been addressed in subsequent updates.
Affected Version(s)
DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4
DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3
DSpace = 10-rc1 = 10-rc1
