Path Traversal Vulnerability in Vanna by Vanna Ltd.
CVE-2026-65702
Key Information:
Badges
What is CVE-2026-65702?
The Vanna application prior to version 2.0.2 has a path traversal flaw within its FileSystemConversationStore persistence integration. This vulnerability permits unauthenticated remote attackers to exploit the conversation_id parameter in the chat API. By injecting path traversal sequences, attackers can evade the designated base directory during file read and write actions. This may lead to unauthorized writing of JSON files to any location in the filesystem and the ability to read sensitive conversation metadata outside the intended directory, posing significant security risks to users and server data integrity.
Affected Version(s)
vanna 0 <= 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
