
CVE-2026-45230 DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated… https://www.cve.org/CVERecord?id=CVE-2026-45230
Post summary
DumbAssets through 1.0.11 contains a path traversal flaw in the POST /api/delete-file endpoint, enabling unauthenticated deletions.



