CVE-2026-100520
published 2026-09-26CVE-2026-100520: Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.94%
59.5th percentile
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| crivion | laranode | < 1.2.1 | 1.2.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home director
ghsa_unreviewed·2026-09-26
CVE-2026-100520 [HIGH] CWE-22 Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home director
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
VulDB
crivion Laranode up to 1.2.0 /filemanager/upload-file path path traversal
vuldb·2026-09-26·CVSS 8.8
CVE-2026-100520 [HIGH] crivion Laranode up to 1.2.0 /filemanager/upload-file path path traversal
A vulnerability classified as critical was found in crivion Laranode up to 1.2.0. The impacted element is an unknown function of the file /filemanager/upload-file. Executing a manipulation of the argument path can lead to path traversal.
The identification of this vulnerability is CVE-2026-100520. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/crivion/laranodehttps://github.com/crivion/laranode/blob/v1.2/app/Actions/Filemanager/UploadFileAction.phphttps://github.com/crivion/laranode/commit/5c2b18ae99caf77a6fb6cc5c0ab66562bd673424https://github.com/crivion/laranode/pull/21https://github.com/crivion/laranode/releases/tag/v1.2.1https://github.com/crivion/laranode/security/advisories/GHSA-34h2-2696-vfvrhttps://www.vulncheck.com/advisories/laranode-before-1.2.1-path-traversal-in-file-manager-upload-endpoint
2026-09-26
Published