Path Traversal in blackms aistack Affecting Static File Handler Functionality
CVE-2026-81560
Key Information:
Badges
What is CVE-2026-81560?
A vulnerability exists in blackms aistack up to version 1.6.1, impacting the Static File Handler component located in src/web/server.ts. This flaw allows for path traversal due to improper handling of the req.url argument, which can be exploited remotely. The exploit code is publicly accessible, posing a significant risk to affected users. The development team has been made aware of this issue through a prior report but has yet to issue a response or patch.
Affected Version(s)
aistack 1.6.0
aistack 1.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
