Path Traversal Vulnerability in YunaiV/zhijiantianya ruoyi-vue-pro File Upload
CVE-2026-97323

5.3MEDIUM

Key Information:

Vendor

Yunaiv

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97323?

A vulnerability exists in YunaiV/zhijiantianya ruoyi-vue-pro that allows attackers to exploit the function 'getOriginalFilename' within the File Upload component, specifically in the 'MpMaterialServiceImpl.java' file. This flaw can lead to an unauthorized path traversal, enabling remote attackers to manipulate file paths and potentially access sensitive files on the server. The issue has been publicly disclosed, putting users at risk. Notably, the vendor was informed of this vulnerability prior to the public disclosure but did not respond or take action.

Affected Version(s)

ruoyi-vue-pro 2026.08

ruoyi-vue-pro 2026.08

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liuyulin (VulDB User)
VulDB CNA Team
.