Unauthenticated URL Fetching in kkFileView by kekingcn
CVE-2026-73243
5.8MEDIUM
What is CVE-2026-73243?
kkFileView, a file online preview project based on Spring Boot, contains a vulnerability that allows unauthorized users to exploit an unauthenticated endpoint. Specifically, the /addTask endpoint was inadvertently excluded from critical filters, permitting attackers to retrieve a URL of their choice. This security flaw results from a weak handling of the fullfilename parameter within the FileHandlerService. The issue has been remediated in version 5.0.1, emphasizing the importance of timely updates to safeguard against potential exploits.
Affected Version(s)
kkFileView < 5.0.1
