Description
The product accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.
CVE vulnerabilities with CWE-50 (2)
8.2
CVSS
HIGH
CVE-2026-66835
pub. 2026-09-01
7.5
CVSS
HIGH
CVE-2023-34092
pub. 2023-06-01