Back to overview

CVE-2026-13528

HIGH
7.3
CVSS 3.1
Description
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the component AppFileController File Upload Endpoint. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The patch is named 4ae3f6b2c9883978837638c14e3d18419819eeb0. It is recommended to apply a patch to fix this issue. This product is published by multiple vendors.

Metadata

CVE ID
CVE-2026-13528
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 07:56 UTC
Published
2026-06-29 02:45 UTC
Last updated
2026-06-29 02:45 UTC
Primary CWE
CWE-22
Path Traversal
Vendor / Product
YunaiV / ruoyi-vue-pro
Sources
cve.org  ·  NVD

Severity & Metrics

7.3 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Affected products (2)
VendorProductPlatformVersions
YunaiV ruoyi-vue-pro 2026.04-jdk8-SNAPSHOT
zhijiantianya ruoyi-vue-pro 2026.04-jdk8-SNAPSHOT
Weakness (CWE)
CWESourceDescription
CWE-22 cna Path Traversal
CVSS scores (4)
ScoreSeverityVersionSourceVector
7.5 N/D 2.0 cna AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C
7.3 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
7.3 HIGH 3.0 cna CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
References (8)
Back to overview