{"id":"CVE-2016-10726","aliases":["GHSA-4m9r-5gqp-7j82"],"url":"https://o3.security/vulnerability/CVE-2016-10726","summary":"High severity vulnerability that affects org.dspace:dspace-xmlui","details":"The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.","published":"2018-07-10T11:29:00.223Z","modified":"2026-07-22T03:44:37.720381Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.dspace:dspace-xmlui","fixedVersion":"4.5"},{"ecosystem":"Maven","name":"org.dspace:dspace-xmlui","fixedVersion":"5.5"},{"ecosystem":"Maven","name":"org.dspace:dspace-xmlui","fixedVersion":"3.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/DSpace/DSpace/releases/tag/dspace-5.5"},{"type":"ADVISORY","url":"https://wiki.duraspace.org/display/DSDOC5x/Release+Notes"},{"type":"FIX","url":"https://jira.duraspace.org/browse/DS-3094"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10726"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4m9r-5gqp-7j82"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T03:44:37.720381Z"}}