CVE-2026-35174Disclosure(chyrplite / chyrp_lite)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch chyrplite chyrp_lite systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to any folder. This vulnerability allows the user to download any file on the server, including config.json.php with database credentials and overwrite critical system files, leading to remote code execution. This vulnerability is fixed in 2026.01.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chyrp_lite

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
chyrp_lite

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 304-06
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35174: CRITICAL] Chyrp Lite prior to 2026.01 had a path traversal vulnerability in the admin console enabling unauthorized access and potential remote code execution, now resolved in version 2026.01.#cve,CVE-2026-35174,#cybersecurity https://cvefind.com/CVE-2026-35174

    Post summary

    The post announces a critical path traversal issue in Chyrp Lite that is now fixed in version 2026.01, without mentioning any exploit code, active attacks, or false-positive claims.

    0000036
    619 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35174 Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator… https://www.cve.org/CVERecord?id=CVE-2026-35174

    Post summary

    The text discloses a path traversal vulnerability in Chyrp Lite versions prior to 2026.01, providing technical details via a CVE record link without any mention of PoC, exploitation, patch, or false‑positive status.

    00000229
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35174: Chyrp Lite has a Path Traversal ... Admin-level path traversal in Chyrp Lite lets you rewrite uploads path, exfil config.json.php with DB creds, then overw... https://zerodaysignal.com/vulnerability/CVE-2026-35174 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A path‑traversal vulnerability (CVE-2026‑35174) in Chyrp Lite allows an attacker to rewrite upload paths and extract database credentials. The tweet reports the flaw but provides no PoC, active exploitation evidence, or patch information.

    0000055
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchyrplitechyrp_lite---

Explore more