Path Traversal Vulnerability in Proma File Preview Service by proma-ai
CVE-2026-88790

2.4LOW

Key Information:

Vendor

Proma-ai

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88790?

A significant security flaw exists in the File Preview Service of Proma, specifically in the resolveTargetPath function. This vulnerability allows for path traversal due to improper handling of the file_path argument, which requires local access for exploitation. The issue has been publicly disclosed and poses a risk if not addressed. To secure your system, it is critical to upgrade to version 0.19.52 or later, which includes a patch addressing this vulnerability (commit ID: b7bf78ab74b1552c92fc98c7db9a8a8d92c631df). Notably, the vulnerability persists with basename-collision fallback issues, independent of the parameter name changes introduced in later versions.

Affected Version(s)

Proma 0.16.3

Proma 0.16.9

Proma 0.17.1

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zhuke (VulDB User)
.