{"id":"CVE-2026-40163","aliases":["GHSA-32pv-mpqg-h292"],"url":"https://o3.security/vulnerability/CVE-2026-40163","summary":"Saltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory read","details":"Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write a changes.json file with attacker-controlled JSON content anywhere on the server filesystem. The GET /sync/upload_finished endpoint allows an unauthenticated attacker to list arbitrary directory contents and read specific JSON files. This vulnerability is fixed in 1.4.5, 1.5.5, and 1.6.0-beta.4.","published":"2026-04-10T17:07:49.067Z","modified":"2026-08-12T03:51:34.125942126Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@saltcorn/server","fixedVersion":"1.4.5"},{"ecosystem":"npm","name":"@saltcorn/server","fixedVersion":"1.5.5"},{"ecosystem":"npm","name":"@saltcorn/server","fixedVersion":"1.6.0-beta.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40163.json"},{"type":"ADVISORY","url":"https://github.com/saltcorn/saltcorn/security/advisories/GHSA-32pv-mpqg-h292"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40163"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.125942126Z"}}