Path Traversal Vulnerability in Proma File Preview Service by proma-ai
CVE-2026-88790
2.4LOW
What is CVE-2026-88790?
A significant security flaw exists in the File Preview Service of Proma, specifically in the resolveTargetPath function. This vulnerability allows for path traversal due to improper handling of the file_path argument, which requires local access for exploitation. The issue has been publicly disclosed and poses a risk if not addressed. To secure your system, it is critical to upgrade to version 0.19.52 or later, which includes a patch addressing this vulnerability (commit ID: b7bf78ab74b1552c92fc98c7db9a8a8d92c631df). Notably, the vulnerability persists with basename-collision fallback issues, independent of the parameter name changes introduced in later versions.
Affected Version(s)
Proma 0.16.3
Proma 0.16.9
Proma 0.17.1
