CVE-2026-61505 UNKNOWN

CVE-2026-61505

Published: 2026-07-13

Description

Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the shared folders. Exploitation is constrained to files matching a narrow naming and format pattern, limiting practical impact.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…