
Ryx@PadhiyarRushi
DropzoneFileExplorer chunked upload trusts fileName all the way to fopen()!! CVE-2026-104826 (CVSS 8.5). v1.1. Traversal walks out of the storage root into the web root. PHP runs. Auth required unless AUTH_ENABLE=false. CVE assigned 2 Oct. Fixed in v1.2. PoC dropped 3 Oct!! https://github.com/kiwknr/CVE-2026-104826 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #RCE #FileUpload
03050383
952 followersView on X
