CVE-2026-4285General

LOWCVSS 2.0 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/Pdf2MdUtil.java. Such manipulation of the argument fileUrl leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-17: 3Technical Details · 2026-03-17: 203-17
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4285 📊 Severity: 2.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4285 #CVE-2026-4285 #CVE #Low  #CyberSecurity #InfoSec https://t.co/qpUGkQ035s

    Post summary

    A short announcement of CVE‑2026‑4285, noting its low severity and listing a generic NVD link, with no technical, exploit, or mitigation details.

    0000041
    101 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4285 A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-mo… https://www.cve.org/CVERecord?id=CVE-2026-4285

    Post summary

    The message discloses CVE-2026-4285, noting a vulnerability in the recognizeMarkdown function of taoofagi easegen-admin; no PoC, exploit, or patch information is provided.

    0000080
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4285 - taoofagi easegen-admin http://Pdf2MdUtil.java recognizeMarkdown path traversal Intel Report: https://ift.tt/2VZhiHk

    Post summary

    An alert announces CVE-2026‑4285, a path‑traversal vulnerability in taoofagi easegen‑admin, and references an Intel report link.

    0000042
    336 followersView on X

Explore more