CVE-2026-38360Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-05-12); latest day: 3
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-05-10: 1Mentions · 2026-05-12: 4Mentions · 2026-06-11: 3Technical Details · 2026-05-10: 1Technical Details · 2026-05-12: 3Technical Details · 2026-06-11: 305-1005-1206-11
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-101
Disclosure1
2026-05-124
Disclosure2General2
2026-06-113
Disclosure2General1
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Data Upload Trap: CVE-2026-38360 Turns fohrloop dash-uploader Into Arbitrary Code Execution On May 8, 2026, security researchers disclosed CVE-2026-38360, a critical directory traversal vulnerability in fohrloop dash-uploader, a widely-used Python package for handling…

    Post summary

    Security researchers disclosed CVE-2026-38360, a directory traversal vulnerability in the fohrloop dash-uploader Python package that can lead to arbitrary code execution.

    1000038
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-38360 · 9.8 → v0.1.0 The Data Upload Trap: CVE-2026-38360 Turns fohrloop dash-uploader Into Arbitrary Code Execution

    Post summary

    The note announces CVE‑2026‑38360 as a severe (9.8) vulnerability that allows arbitrary code execution in fohrloop dash‑uploader, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    1000035
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Critical directory traversal vulnerability (CVE-2026-38360, CVSS 9.8) in fohrloop dash-uploader (v0.1.0–v0.7.0a2) allows unauthenticated remote attackers to achieve arbitrary code execution via path manipulation in file upload handling. Published May 8, 2026. No…

    Post summary

    The post announces a critical directory traversal vulnerability (CVE-2026-38360) in fohrloop dash-uploader, enabling unauthenticated remote attackers to execute code via path manipulation during file uploads.

    1000038
    266 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-38360 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text references CVE-2026-38360 with a critical CVSS score but provides no evidence of exploitation, PoC, or mitigation.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-38360 (CVSS 9.8) — multiple products. CVE: CVE-2026-38360 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-38360 as a critical vulnerability (CVSS 9.8) affecting multiple products, yet it offers no PoC, exploit code, or patch information.

    1000022
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-38360 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via…

    Post summary

    The advisory announces a critical directory traversal flaw in fohrloop dash‑uploader that permits remote code execution, with a CVSS score of 9.8, but provides no PoC or exploit details.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-38360-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text merely includes a link and hashtags with no substantive information about the CVE beyond its identifier.

    0000024
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-38360 Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httpreq… https://www.cve.org/CVERecord?id=CVE-2026-38360

    Post summary

    The tweet announces a new directory traversal vulnerability in fohrloop dash-uploader that could enable remote code execution, but provides no PoC, exploit, or patch details.

    00000170
    57.5K followersView on X

Explore more