CRITICAL🇵🇱 Wersja polska

CVE-2026-22783

CVSS 9.6v3.1pub. 2026-01-12upd. 2026-01-16

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in the delete operation enables authenticated users to delete arbitrary filesystem paths. The vulnerability manifests through a three-step attack chain: authenticated users upload a file to the datastore, update the file's file_local_name field to point to an arbitrary filesystem path through mass assignment, then trigger the delete operation which removes the target file without path validation. This vulnerability is fixed in 2.4.24.

🤖 AI Analysis
How it works

The attack proceeds in three steps: an authenticated user first uploads an arbitrary file to the datastore, then uses mass assignment to overwrite the 'file_local_name' field pointing to a selected, arbitrary path in the server's file system. In the final step, the user invokes a file deletion operation, which is executed without any path validation, causing the indicated resource to be deleted. Path traversal protection mechanisms or whitelisting of permitted locations are not applied in vulnerable versions.

Impact

An attacker can permanently delete any files accessible to the application process on the server, which may lead to data destruction, disruption of the operating system or other applications, as well as preventing the DFIR-IRIS platform itself from functioning.

Mitigation & patch

DFIR-IRIS Iris should be updated to version 2.4.24 or later, in which the vulnerability has been fixed. The patch is available in the vendor's repository (commit 57c1b80494bac187893aebc6d9df1ce6e56485b7).

Who is affected

DFIR-IRIS Iris in versions prior to 2.4.24

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
  • Dfir Iris Iris

    APP
    Dfir-Iris
    < 2.4.24
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-25624MEDIUM6.8same product

Iris is a web collaborative platform aiming to help incident responders sharing technical details during inves...

CVE-2024-25640MEDIUM4.6same product

Iris is a web collaborative platform that helps incident responders share technical details during investigati...

CVE-2023-50712MEDIUM4.6same product

Iris is a web collaborative platform aiming to help incident responders sharing technical details during inves...

CVE-2023-30615MEDIUM6.3same product

Iris is a web collaborative platform aiming to help incident responders sharing technical details during inves...