CVE-2026-41951Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is running in GROWI.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-11: 3Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-11: 3Technical Details · 2026-05-12: 105-1105-12
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-113
Disclosure3
2026-05-121
Disclosure1
Full discourse4 posts
  • Mr.Rabbit@01ra66it
    Disclosure

    【JVN#38788367: GROWIにおけるパストラバーサルの脆弱性】 JVNは、GROWI v7.5.0およびそれ以前にパストラバーサル脆弱性 CVE-2026-41951 が存在すると公表しました。GROWIにメールサーバーが設定されている場合にのみ影響を受け、攻撃者の用意したESJテンプレートがサーバ上で実行される可能性があります。 GROWIは社内Wikiやナレッジ基盤として利用されることが多く、内部手順、設計情報、運用メモ、API仕様、障害対応履歴が集まりやすいサービスです。脆弱性悪用により任意OSコマンド実行、コード実行、サービス停止につながる可能性がある点は重く見るべきです。 防御側は、GROWIのバージョン、メールサーバー設定の有無、公開範囲、管理者アカウント、テンプレート実行ログを確認してください。対象環境ではv7.5.1への更新を優先し、侵害が疑われる場合はサーバ上の不審プロセス、ファイル作成、外向き通信を確認する必要があります。 #GROWI #JVN #CVE202641951 #社内Wiki #ナレッジ管理 #脆弱性対応 https://jvn.jp/jp/JVN38788367/index.html

    Post summary

    JVN announced a path‑traversal vulnerability (CVE‑2026‑41951) in GROWI v7.5.0 and earlier, which can lead to arbitrary OS command execution when a mail server is configured; users are advised to upgrade to v7.5.1.

    00010273
    3.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41951 Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS templates on the server when an email server is … https://www.cve.org/CVERecord?id=CVE-2026-41951

    Post summary

    A path traversal vulnerability in GROWI v7.5.0 and earlier could enable execution of arbitrary EJS templates; no patch or exploit details are provided.

    00010113
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41951 Path Traversal Vulnerability in GROWI v7.5.0 Enabling Arbitrary EJS Template Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41951

    Post summary

    A new CVE, CVE-2026-41951, has been disclosed as a Path Traversal vulnerability in GROWI v7.5.0 that can lead to arbitrary EJS template execution, but no proof of concept, exploit, or active exploitation has been reported.

    0000039
    4.0K followersView on X
  • Entity@0x2ed3bb60
    Disclosure

    🚨 HIGH: CVE-2026-41951 permits path traversal in GROWI v7.5.0 and earlier. Attacker achieves arbitrary EJS template execution when email server is active. Entity correlation: surface is viable, patch gate is mandatory. https://0x2ed3bb60.xyz/threat/b575edc4f3a15f7a

    Post summary

    A high‑severity CVE‑2026‑41951 enables path traversal and arbitrary EJS template execution in GROWI v7.5.0 and earlier, and requires a patch.

    0000027
    7 followersView on X

Explore more